Ticket #1181 (new defect) — at Version 1
Link spam vulnerability in Notes and User-About fields
Reported by: | dread | Owned by: | dread |
---|---|---|---|
Priority: | blocker | Milestone: | |
Component: | ckan | Keywords: | |
Cc: | Repository: | ckan | |
Theme: | none |
Description (last modified by dread) (diff)
When viewing a user and a package, the about/notes fields contain Markdown, which may have links. These should have rel="nofollow" to discourage link spam.
Change History
Note: See
TracTickets for help on using
tickets.