Skip to content

Commit c729aa2

Browse files
author
Владислав Савченко
committed
Fix potential XSS vulnerability in break_long_headers template filter (encode#9435)
1 parent 2da473c commit c729aa2

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rest_framework/templatetags/rest_framework.py

+1-1
Original file line numberDiff line numberDiff line change
@@ -318,5 +318,5 @@ def break_long_headers(header):
318318
when possible (are comma separated)
319319
"""
320320
if len(header) > 160 and ',' in header:
321-
header = mark_safe('<br> ' + ', <br>'.join(header.split(',')))
321+
header = mark_safe('<br> ' + ', <br>'.join(escape(header).split(',')))
322322
return header

0 commit comments

Comments
 (0)