File tree 2 files changed +5
-0
lines changed
2 files changed +5
-0
lines changed Original file line number Diff line number Diff line change @@ -42,6 +42,7 @@ All notable changes to Gogs are documented in this file.
42
42
- [ Security] Potential XSS attack via ` .ipynb ` . [ #5170 ] ( https://github.com/gogs/gogs/issues/5170 )
43
43
- [ Security] Potential SSRF attack via webhooks. [ #5366 ] ( https://github.com/gogs/gogs/issues/5366 )
44
44
- [ Security] Potential CSRF attack in admin panel. [ #5367 ] ( https://github.com/gogs/gogs/issues/5367 )
45
+ - [ Security] Potential stored XSS attack in some browsers. [ #5397 ] ( https://github.com/gogs/gogs/issues/5397 )
45
46
- [ Security] Potential RCE on mirror repositories. [ #5767 ] ( https://github.com/gogs/gogs/issues/5767 )
46
47
- [ Security] Potential XSS attack with raw markdown API. [ #5907 ] ( https://github.com/gogs/gogs/pull/5907 )
47
48
- Open/close milestone redirects to a 404 page. [ #5677 ] ( https://github.com/gogs/gogs/issues/5677 )
Original file line number Diff line number Diff line change @@ -336,6 +336,10 @@ func Contexter() macaron.Handler {
336
336
337
337
c .renderNoticeBanner ()
338
338
339
+ // 🚨 SECURITY: Prevent MIME type sniffing in some browsers,
340
+ // see https://github.com/gogs/gogs/issues/5397 for details.
341
+ c .Header ().Set ("X-Content-Type-Options" , "nosniff" )
342
+
339
343
ctx .Map (c )
340
344
}
341
345
}
You can’t perform that action at this time.
0 commit comments