Page MenuHomePhabricator

Fix a self-XSS hole in Diffusion
ClosedPublic

Authored by epriestley on Mar 20 2015, 9:43 PM.
Tags
None
Referenced Files
F18411211: D12117.id.diff
Sat, Aug 30, 5:45 AM
F18402419: D12117.diff
Fri, Aug 29, 8:24 PM
F18108041: D12117.id29143.diff
Aug 11 2025, 4:38 AM
F18092795: D12117.id29140.diff
Aug 7 2025, 1:12 PM
F17949616: D12117.id29140.diff
Jul 31 2025, 11:43 PM
F17949357: D12117.id29140.diff
Jul 31 2025, 11:18 PM
F17941057: D12117.diff
Jul 31 2025, 5:01 AM
F17867817: D12117.id.diff
Jul 28 2025, 6:45 AM
Subscribers

Details

Reviewers
btrahan
chad
Commits
Restricted Diffusion Commit
rPac029d0a50e7: Fix a self-XSS hole in Diffusion
Summary

Via HackerOne. We aren't correctly escaping the date, so a user can XSS themselves by setting their date format creatively.

This construction is very unusual and I don't think we do anything similar elsewhere, so I can't come up with a systematic change which would prevent this in the general case.

Test Plan

Set date format to tag junk, got self-XSS before patch and proper escaping after the patch.

Diff Detail

Repository
rP Phabricator
Branch
xss1
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 4930
Build 4948: [Placeholder Plan] Wait for 30 Seconds

Event Timeline

epriestley retitled this revision from to Fix a self-XSS hole in Diffusion.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added reviewers: chad, btrahan.
chad edited edge metadata.
This revision is now accepted and ready to land.Mar 20 2015, 9:49 PM
This revision was automatically updated to reflect the committed changes.