Ticket #1181 (new defect) — at Version 1
Link spam vulnerability in Notes and User-About fields
| Reported by: | dread | Owned by: | dread |
|---|---|---|---|
| Priority: | blocker | Milestone: | |
| Component: | ckan | Keywords: | |
| Cc: | Repository: | ckan | |
| Theme: | none |
Description (last modified by dread) (diff)
When viewing a user and a package, the about/notes fields contain Markdown, which may have links. These should have rel="nofollow" to discourage link spam.
Change History
Note: See
TracTickets for help on using
tickets.
