-
### Issue Summary
A **Stored Cross-Site Scripting (XSS)** vulnerability has been identified in the `/pathinfo` endpoint of the project. This vulnerability allows an attacker to inject malicious Jav…
-
### Checklist
- [X] I have searched the [existing issues](https://github.com/streamlit/streamlit/issues) for similar issues.
- [X] I added a very descriptive title to this issue.
- [X] I have provide…
-
The installation of BBB 2.5.4 (with bbb-install-2.5) does not set http security headers like content-security-policy, x-frame-options, hsts, x-content-type-options.
Is there any reason for not usi…
-
-
I have tried this on https://mysignins.microsoft.com/security-info choose Add new authentication method > Authenticator > not microsoft authenticator > grab the secret key, generate the 6 digits token…
-
https://observatory.mozilla.org
-
- Confidentialy and intergrity
-
What is the state of the security issues Alan mentioned today ? were they done.
1. בתור התחלה, תאבטחו את השרת ושלפחות ה login יהיה ב HTTPS ולא ב HTTP.
feed back I got from a user -
![image](https…
-
```
❯ composer audit
Found 1 security vulnerability advisory affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package…
-
Currently, the TD allows quite a lot of flexibility for HTTP BasicAuth and API Key (others too but let's start here?). I was talking about this with @danielpeintner on Wednesday and also supervising @…