01f4542b84
- update to 1.7.6: major update from 1.7.5.x * Similar to branch names, tagnames that begin with "-" are now disallowed. * Simpler handling of a large file depending on core.bigfilethreshold value * A magic pathspec ":/" handling * Some new options and improvements in git-blame, git-commit, git-diff git-grep, git-format-patch, git-merge, git-svn, etc * More prepartaion for i18n/l10n. See Documentation/RelNotes/1.7.6.txt for details. - updated to git 1.7.6: see git changelog for more details OBS-URL: https://build.opensuse.org/request/show/74766 OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/git?expand=0&rev=64
53 lines
1.8 KiB
Diff
53 lines
1.8 KiB
Diff
From: Jakub Narebski <jnareb@...il.com>
|
|
Subject: [PATCH] gitweb: Enable $prevent_xss by default
|
|
|
|
This fixes issue CVE-2011-2186 originally reported in
|
|
https://launchpad.net/bugs/777804
|
|
|
|
Reported-by: dave b <db.pub.mail@...il.com>
|
|
Signed-off-by: Jakub Narebski <jnareb@...il.com>
|
|
---
|
|
git-instaweb.sh | 4 ++++
|
|
gitweb/README | 5 +++--
|
|
gitweb/gitweb.perl | 2 +-
|
|
3 files changed, 8 insertions(+), 3 deletions(-)
|
|
|
|
--- a/git-instaweb.sh
|
|
+++ b/git-instaweb.sh
|
|
@@ -583,6 +583,10 @@
|
|
our \$git_temp = "$fqgitdir/gitweb/tmp";
|
|
our \$projects_list = \$projectroot;
|
|
|
|
+# we can trust our own repository, so disable XSS prevention
|
|
+# to enable some extra features
|
|
+our \$prevent_xss = 0;
|
|
+
|
|
\$feature{'remote_heads'}{'default'} = [1];
|
|
EOF
|
|
}
|
|
--- a/gitweb/README
|
|
+++ b/gitweb/README
|
|
@@ -131,8 +131,9 @@
|
|
* $prevent_xss
|
|
If true, some gitweb features are disabled to prevent content in
|
|
repositories from launching cross-site scripting (XSS) attacks. Set this
|
|
- to true if you don't trust the content of your repositories. The default
|
|
- is false.
|
|
+ to false if you trust the content of your repositories, and want to use
|
|
+ per-repository README.html, or use gitweb as deployment platform
|
|
+ via 'blob_plain' view and path_info links. The default is true.
|
|
* $maxload
|
|
Used to set the maximum load that we will still respond to gitweb queries.
|
|
If server load exceed this value then return "503 Service Unavailable" error.
|
|
--- a/gitweb/gitweb.perl
|
|
+++ b/gitweb/gitweb.perl
|
|
@@ -170,7 +170,7 @@
|
|
|
|
# Disables features that would allow repository owners to inject script into
|
|
# the gitweb domain.
|
|
-our $prevent_xss = 0;
|
|
+our $prevent_xss = 1;
|
|
|
|
# Path to the highlight executable to use (must be the one from
|
|
# http://www.andre-simon.de due to assumptions about parameters and output).
|