Embedded URLs appended to legit DNS doesn't get flagged #53

Open
opened 2025-06-03 16:15:03 +00:00 by sumantrom · 4 comments

Bugs link at th moment has to
a) 1 each line
b) Gitlab,RHBZ,pagure, gitea... BUT when you embedd a URL it gets accepted which is not good.
It is how people will be able to download anything in the App server and client end just by a click

Bugs link at th moment has to a) 1 each line b) Gitlab,RHBZ,pagure, gitea... BUT when you embedd a URL it gets accepted which is not good. It is how people will be able to download anything in the App server and client end just by a click
Author
example is https://www.redhat.com/en/search?search=https://communityblog.fedoraproject.org/feed, you can find it on https://testdays.fedoraproject.org/testday/1
Owner

Please use the staging testdays instance for testing, not the production one.

Please use the **staging** testdays instance for testing, not the production one.
Owner

It is how people will be able to download anything in the App server and client end just by a click

I don't understand this. Assuming there is an attacker which received the creator or admin role, and can just adjust testcase hyperlinks, what exactly can they do?

> It is how people will be able to download anything in the App server and client end just by a click I don't understand this. Assuming there is an attacker which received the `creator` or `admin` role, and can just adjust testcase hyperlinks, what exactly can they do?
Owner

@sumantrom Hi, can you explain this in more detail?

@sumantrom Hi, can you explain this in more detail?
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
quality/testdays-web#53
No description provided.