IACR / conference-template

Reusable conference website template for all IACR events
6 stars 9 forks source link

XSS Security problems with bootstrap 3.3.7 #153

Closed kmccurley closed 5 years ago

kmccurley commented 5 years ago

I ran audits on pkc.iacr.org/2018 and found that chrome complains about potential XSS security problems in bootstrap 3.3.7. We have been planning to do a revision on the conference template anyway, and moving to bootstrap 4.1.3 is probably a good idea. There is only an urgency if the site is modified to use authentication, and so far I think only Crypto 2018 did that.

kaymckelly commented 5 years ago

All offsite content will be removed with the 4.3 upgrade, so this will no longer be a concern.