Page MenuHomePhabricator

Fix a self-XSS hole in Diffusion
ClosedPublic

Authored by epriestley on Mar 20 2015, 9:43 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Apr 25, 1:49 AM
Unknown Object (File)
Sun, Apr 7, 11:28 AM
Unknown Object (File)
Thu, Apr 4, 9:25 AM
Unknown Object (File)
Tue, Apr 2, 9:50 AM
Unknown Object (File)
Mar 29 2024, 9:49 PM
Unknown Object (File)
Mar 28 2024, 3:14 PM
Unknown Object (File)
Mar 10 2024, 7:48 AM
Unknown Object (File)
Feb 13 2024, 1:10 AM
Subscribers

Details

Reviewers
btrahan
chad
Commits
Restricted Diffusion Commit
rPac029d0a50e7: Fix a self-XSS hole in Diffusion
Summary

Via HackerOne. We aren't correctly escaping the date, so a user can XSS themselves by setting their date format creatively.

This construction is very unusual and I don't think we do anything similar elsewhere, so I can't come up with a systematic change which would prevent this in the general case.

Test Plan

Set date format to tag junk, got self-XSS before patch and proper escaping after the patch.

Diff Detail

Repository
rP Phabricator
Branch
xss1
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 4930
Build 4948: [Placeholder Plan] Wait for 30 Seconds

Event Timeline

epriestley retitled this revision from to Fix a self-XSS hole in Diffusion.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added reviewers: chad, btrahan.
chad edited edge metadata.
This revision is now accepted and ready to land.Mar 20 2015, 9:49 PM
This revision was automatically updated to reflect the committed changes.