The pve GUI allows you to add simple HTML formatting tags into notes like "br" (with less-than and greater-than) to do some have control over line breaks.
This works: the GUI now shows notes with proper line breaks.
But it breaks pve Option and HArdware settings. Any attempt to change any Hardwaer setting results in "parse error" errors.
All previous pending changes remain pending and are not applied when the VM shuts down.
Either prevent HTML tags in notes or fix the parser to ignore the notes.
I have not even tried to see if this parser flaw can be exploited by unprivileged accounts gaining elevated access by carefully crafted Notes.
This works: the GUI now shows notes with proper line breaks.
But it breaks pve Option and HArdware settings. Any attempt to change any Hardwaer setting results in "parse error" errors.
All previous pending changes remain pending and are not applied when the VM shuts down.
Either prevent HTML tags in notes or fix the parser to ignore the notes.
I have not even tried to see if this parser flaw can be exploited by unprivileged accounts gaining elevated access by carefully crafted Notes.