Page MenuHomePhabricator

Fix a self-XSS hole in Diffusion
ClosedPublic

Authored by epriestley on Mar 20 2015, 9:43 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Apr 7, 11:28 AM
Unknown Object (File)
Thu, Apr 4, 9:25 AM
Unknown Object (File)
Tue, Apr 2, 9:50 AM
Unknown Object (File)
Fri, Mar 29, 9:49 PM
Unknown Object (File)
Thu, Mar 28, 3:14 PM
Unknown Object (File)
Mar 10 2024, 7:48 AM
Unknown Object (File)
Feb 13 2024, 1:10 AM
Unknown Object (File)
Jan 23 2024, 7:07 PM
Subscribers

Details

Reviewers
btrahan
chad
Commits
Restricted Diffusion Commit
rPac029d0a50e7: Fix a self-XSS hole in Diffusion
Summary

Via HackerOne. We aren't correctly escaping the date, so a user can XSS themselves by setting their date format creatively.

This construction is very unusual and I don't think we do anything similar elsewhere, so I can't come up with a systematic change which would prevent this in the general case.

Test Plan

Set date format to tag junk, got self-XSS before patch and proper escaping after the patch.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Fix a self-XSS hole in Diffusion.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added reviewers: chad, btrahan.
chad edited edge metadata.
This revision is now accepted and ready to land.Mar 20 2015, 9:49 PM
This revision was automatically updated to reflect the committed changes.