Via security@apache.org report
...
3. Go to http://localhost:8080/auth/preferences/ and set
"<script>confirm(1)</script>" (without the quotes) as your Display Name
under Preferences / General Settings. Save.4. As test-user, create a new Project. Let's assume the URL for the
project is http://localhost:8080/p/abc5. For that Project, go to http://localhost:8080/p/abc/tickets/new/
6. In the Owner dropdown on the Create Ticket page, type the letter "s"
...
Here is a fix that I have come up with. Not committing to master yet until other security steps are completed.
This diff looks good to me, clear for merge.
Committed to master.