Markup injection

kjr

Posted on
Mar 29 2018

Got an error report where some markup (jsx) from the stack trace is being rendered in the raygun ui:

https://app.raygun.com/crashreporting/o25923/errors/2349822309?dateFrom=2018-03-28T02%3A01%3A00.000Z&dateTo=2018-03-28T14%3A53%3A39.000Z

This makes the stack trace hard to read, but having it render markup at all from the stack trace is dangerous


John-Daniel Trask

Raygun

Posted on
Apr 03 2018

Hi Kjr,

Thanks for reporting this. The team resolved this right after you reported it so hopefully you're able to read the stack traces now (and furthermore, close off a security hole).

Let us know if you have any further issues!

Kind regards,

John-Daniel Trask


Reply