NewsPanel: Fixed XSS issue when rendering rss links (#27612)

This commit is contained in:
Torkel Ödegaard 2020-09-16 11:15:56 +02:00 committed by GitHub
parent 58124efdb5
commit b58864792d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -77,7 +77,7 @@ export class NewsPanel extends PureComponent<Props, State> {
{news.map((item, index) => { {news.map((item, index) => {
return ( return (
<div key={index} className={styles.item}> <div key={index} className={styles.item}>
<a href={item.link} target="_blank"> <a href={textUtil.sanitizeUrl(item.link)} target="_blank">
<div className={styles.title}>{item.title}</div> <div className={styles.title}>{item.title}</div>
<div className={styles.date}>{dateTimeFormat(item.date, { format: 'MMM DD' })} </div> <div className={styles.date}>{dateTimeFormat(item.date, { format: 'MMM DD' })} </div>
</a> </a>