bcgov / bcgov/entity

UIs: investigate XSS vulnerability with v-html

Open
#12,002 7 comments 0 reactions 0 assignees View on GitHub
ENTITY - DO NOT USE Priority2 security techdebt
Dominant language
JavaScript
Stars
23
Forks
62
Avg merge
24m
Merged PRs (30d)
1

Description

SonarCloud identified the following issue.

We control the content of the v-html value (which is fetched via an API call) though it may possible for a bad actor to inject malicious code here... I'm not sure, and I'm not sure what the risk is. I also don't know how to work around this (needs research).

![image.png](https://images.zenhubusercontent.com/5d0a7edda4644173e93bf808/43645b7b-3d95-43f3-a54b-ae3b0272f53f)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.