This fix was heavily inspired by Mastodon's fix for GHSA-9928-3cp5-93fm. So, thank you Cure53 for finding this issue, thank you Mozilla for paying Cure53 to look into it, and thanks for Mastodon for fixing it. |
||
|---|---|---|
| .. | ||
| atom.rng | ||
| bad_urls.txt | ||
| button.gif | ||
| button.png | ||
| client_assertion_with_nonexistent_client_id.txt | ||
| client_assertion_with_nonexistent_kid.txt | ||
| client_assertion_with_tampered_sig.txt | ||
| evil-image.ps.png | ||
| exif.jpg | ||
| good_urls.txt | ||
| jwks.json | ||
| msg.xml | ||
| msg.xml.clear.asc | ||
| msg.xml.detached.asc | ||
| msg.xml.normal.asc | ||
| public_posts.json | ||
| test.csv | ||
| valid_client_assertion.txt | ||