Comment 4 for bug 1453074

Revision history for this message
Nikita Konovalov (nkonovalov) wrote : Re: help_text parameter of fields is vulnerable to arbitrary html injection

The stack templates may also be downloaded from the insecure resource via http and if there is a MitM attack going on on that resource the heat template using this exploit may be obtained.