view-source: pages can be used to gain cross-origin access to restricted domains
Categories
(WebExtensions :: Untriaged, defect, P2)
Tracking
(Not tracked)
People
(Reporter: qab, Unassigned)
References
Details
(Keywords: csectype-priv-escalation, reporter-external, sec-moderate)
Attachments
(1 file)
1.22 KB,
application/x-zip-compressed
|
Details |
Reporter | ||
Comment 1•8 years ago
|
||
Reporter | ||
Comment 2•8 years ago
|
||
Reporter | ||
Comment 3•8 years ago
|
||
Reporter | ||
Updated•8 years ago
|
Updated•8 years ago
|
Comment 4•8 years ago
|
||
Comment 5•8 years ago
|
||
Comment 6•8 years ago
|
||
Comment 7•8 years ago
|
||
Comment 8•8 years ago
|
||
Comment 9•8 years ago
|
||
Comment 10•8 years ago
|
||
Comment 11•8 years ago
|
||
Updated•8 years ago
|
![]() |
||
Comment 12•8 years ago
|
||
Reporter | ||
Comment 13•8 years ago
|
||
Comment 14•8 years ago
|
||
Reporter | ||
Comment 15•8 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Comment 16•6 years ago
|
||
This bug is still open, but from looking at the comments I think all the individual components (being able to open view-source:about:*, running code on it) have been fixed elsewhere. Is that right? Is there something left to do here?
Reporter | ||
Comment 17•6 years ago
|
||
The original PoC indeed does not work anymore, however, 'view-source:addons.mozilla.org' can still access mozAddons by linking to 'addons.mozilla.org' which I believe is the purpose of this bug. Not sure what the plan is here, is this behavior intended or are we looking to make that not a thing?
Comment 18•6 years ago
•
|
||
(In reply to Abdulrahman Alqabandi from comment #17)
The original PoC indeed does not work anymore, however, 'view-source:addons.mozilla.org' can still access mozAddons by linking to 'addons.mozilla.org' which I believe is the purpose of this bug. Not sure what the plan is here, is this behavior intended or are we looking to make that not a thing?
This is bug 1430257. See also https://bugzilla.mozilla.org/show_bug.cgi?id=1171853#c35 . TL;DR: yes we would like to change this but it hasn't been top of our priority list...
My understanding is that with add-ons as well as the web being unable to link to view-source:addons.mozilla.org, this bug isn't practically exploitable anymore (ie yes the PoC doesn't work anymore, but there isn't really a way to make it work from the same assumptions anymore, either (that we're aware of), right)?
Reporter | ||
Comment 19•6 years ago
|
||
(In reply to :Gijs (he/him) from comment #18)
this bug isn't practically exploitable anymore (ie yes the PoC doesn't work anymore, but there isn't really a way > to make it work from the same assumptions anymore, either (that we're aware of), right)?
Correct. As far as I'm aware this cannot be exploited anymore.
Comment 20•6 years ago
|
||
It'd be nice to make this bug depend on the things that actually fixed it, but marking FIXED anyway (rather than the usual WORKSFORME) because we have decided to award a bounty for it.
Updated•6 years ago
|
Updated•6 years ago
|
Updated•5 years ago
|
Updated•1 year ago
|
Description
•