-
Notifications
You must be signed in to change notification settings - Fork 10.1k
Closed
Labels
content:editRequest for content editsRequest for content editsdocumentationDocumentation editsDocumentation editsproduct:r2R2 object storage: https://developers.cloudflare.com/r2R2 object storage: https://developers.cloudflare.com/r2
Description
Existing documentation URL(s)
What changes are you suggesting?
Hey,
it bugs me that this code example has an obvious XSS vulnerability. The objectName can contain an arbitrary user input that is passed as an unsanitized value to the html response that is returned by objectNotFound. I suggest to fix that.
Best,
Julian
Additional information
No response
Metadata
Metadata
Labels
content:editRequest for content editsRequest for content editsdocumentationDocumentation editsDocumentation editsproduct:r2R2 object storage: https://developers.cloudflare.com/r2R2 object storage: https://developers.cloudflare.com/r2