Closed Bug 1628181 Opened 6 years ago Closed 6 years ago

"><script>alert(1)</script>

Categories

(Invalid Bugs :: General, defect)

3.5 Branch
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED INVALID

People

(Reporter: AJSBD, Unassigned)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.163 Safari/537.36

Steps to reproduce:

"><script>alert(1)</script>
<svg onload=alert(1)>
<img src="" onerror=alert(1)>

Actual results:

"><script>alert(1)</script>
<svg onload=alert(1)>
<img src="" onerror=alert(1)>

Expected results:

"><script>alert(1)</script>
<svg onload=alert(1)>
<img src="" onerror=alert(1)>

[Security approval request comment]
How easily could an exploit be constructed based on the patch?

Do comments in the patch, the check-in comment, or tests included in the patch paint a bulls-eye on the security problem?

Which older supported branches are affected by this flaw?

If not all supported branches, which bug introduced the flaw?

Do you have backports for the affected branches? If not, how different, hard to create, and risky will they be?

How likely is this patch to cause regressions; how much testing does it need?

[Approval Request Comment]
If this is not a sec:{high,crit} bug, please state case for ESR consideration:
User impact if declined:
Fix Landed on Version:
Risk to taking this patch (and alternatives if risky):

See https://wiki.mozilla.org/Release_Management/ESR_Landing_Process for more info.

Approval Request Comment
[Feature/Bug causing the regression]:
[User impact if declined]:
[Is this code covered by automated tests?]:
[Has the fix been verified in Nightly?]:
[Needs manual test from QE? If yes, steps to reproduce]:
[List of other uplifts needed for the feature/fix]:
[Is the change risky?]:
[Why is the change risky/not risky?]:
[String changes made/needed]:

Approval Request Comment
[Feature/Bug causing the regression]:
[User impact if declined]:
[Is this code covered by automated tests?]:
[Has the fix been verified in Nightly?]:
[Needs manual test from QE? If yes, steps to reproduce]:
[List of other uplifts needed for the feature/fix]:
[Is the change risky?]:
[Why is the change risky/not risky?]:
[String changes made/needed]:

Attachment #9139058 - Flags: ui-review+
Attachment #9139058 - Flags: sec-approval?
Attachment #9139058 - Flags: review+
Attachment #9139058 - Flags: feedback+
Attachment #9139058 - Flags: data-review+
Attachment #9139058 - Flags: checkin-
Attachment #9139058 - Flags: approval-mozilla-release?
Attachment #9139058 - Flags: approval-mozilla-esr68?
Attachment #9139058 - Flags: approval-mozilla-beta?
Attachment #9139058 - Flags: a11y-review-

While we appreciate security testing of our products, please don't do this on a live bugzilla environment (or, if you must absolutely, please at least file your bug directly to the invalid bugs component).

Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 6 years ago
Component: Untriaged → General
Flags: ui-review+
Flags: sec-approval?
Flags: checkin-
Flags: approval-mozilla-release?
Flags: approval-mozilla-esr68?
Flags: approval-mozilla-beta?
Flags: a11y-review-
Product: Firefox → Invalid Bugs
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.

Attachment