doc: link CVE [ci skip]
This commit is contained in:
parent
9645b2ed0d
commit
7f518d0ce6
@ -362,11 +362,11 @@ v1.3.3
|
|||||||
Security
|
Security
|
||||||
~~~~~~~~
|
~~~~~~~~
|
||||||
|
|
||||||
- An XSS vulnerability on the `qute://history` page allowed websites to inject
|
- CVE-2018-1000559: An XSS vulnerability on the `qute://history` page allowed
|
||||||
HTML into the page via a crafted title tag. This could allow them to steal
|
websites to inject HTML into the page via a crafted title tag. This could
|
||||||
your browsing history. If you're currently unable to upgrade, avoid using
|
allow them to steal your browsing history. If you're currently unable to
|
||||||
`:history`. A CVE request for this issue is pending, see
|
upgrade, avoid using `:history`. See the related GitHub issue for details:
|
||||||
https://github.com/qutebrowser/qutebrowser/issues/4011[#4011] for updates.
|
https://github.com/qutebrowser/qutebrowser/issues/4011.
|
||||||
|
|
||||||
Fixed
|
Fixed
|
||||||
~~~~~
|
~~~~~
|
||||||
|
Loading…
Reference in New Issue
Block a user