Comment 16 for bug 1327414

Revision history for this message
Thierry Carrez (ttx) wrote : Re: www-authenticate value isn't quoted

@Tristan: I think we just need to say that this allows to inject data in Swift response while still appearing to come from the Swift server, potentially leading to a XSS vulnerability. No need to get too specific on what that would exactly allow.