Open Bug 1203102 Opened 9 years ago Updated 2 years ago

Relax restrictions on <animate> and <set> elements in SVG content in nsTreeSanitizer

Categories

(Core :: DOM: Security, defect, P3)

defect

Tracking

()

People

(Reporter: Gijs, Unassigned)

References

Details

(Whiteboard: [adv-main42-][domsecurity-backlog1])

In bug 1182778 I'm stripping all of <animate> and <set>. In theory, it should be possible to only strip the attributeName if the attribute that's being animated/set is not supposed to be set in the first place. Because of namespaces, I expect that's not trivial.

Marking sec-sensitive because 1182778 is still hidden.
Keywords: sec-other
Group: core-security → dom-core-security
Whiteboard: [adv-main42-]
Can we open this up now?
Flags: needinfo?(gijskruitbosch+bugs)
(In reply to Ryan VanderMeulen [:RyanVM] from comment #1)
> Can we open this up now?

Yes. (I can't, though, so pinging the needinfo back.)
Flags: needinfo?(gijskruitbosch+bugs) → needinfo?(ryanvm)
Group: dom-core-security
Flags: needinfo?(ryanvm)
Component: DOM: Core & HTML → DOM: Security
Severity: normal → S3
Priority: -- → P3
Whiteboard: [adv-main42-] → [adv-main42-][domsecurity-backlog1]
Keywords: sec-other
You need to log in before you can comment on or make changes to this bug.