Closed
Bug 1660704
Opened 5 years ago
Closed 4 years ago
Firefox Android watch to app resource
Categories
(Firefox for Android :: General, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 1684761
People
(Reporter: kiky.tokamuro, Unassigned, NeedInfo)
References
()
Details
(Keywords: reporter-external, sec-low, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Attachments
(2 files)
Firefox ver: 79.0.5 (Build #2015758619)
OS: Android 7.0
Ability to insert payload into "image" parameter on page resource://android/assets/low_and_medium_risk_error_pages.html to view app resources.
Flags: sec-bounty?
Reporter | ||
Updated•5 years ago
|
OS: Unspecified → Android
Updated•5 years ago
|
Group: firefox-core-security → mobile-core-security
Type: task → defect
Component: Security → Security: Android
Product: Firefox → Fenix
Comment 1•5 years ago
|
||
HTML file showing that this is not a problem from remote pages.
Comment 2•5 years ago
|
||
users can load a bunch of internal URLs in the address bar (mostly for testing/debugging) if they want. If it's harmful they're only hurting themselves. It's only a problem if these can be accessed from web content. That's not demonstrated here, but you didn't show the full steps that lead to your picture -- is there a way?
Flags: needinfo?(kiky.tokamuro)
Updated•5 years ago
|
Keywords: sec-low
See Also: → CVE-2021-23959
Updated•5 years ago
|
Flags: sec-bounty? → sec-bounty-
Updated•4 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE
Comment 4•4 years ago
|
||
Updated•4 years ago
|
Group: mobile-core-security
Updated•3 years ago
|
Component: Security: Android → General
Updated•1 year ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•