Closed Bug 1750221 Opened 3 years ago Closed 3 years ago

Blocked about pages in policy can be bypassed by modifying the URL with mixed case

Categories

(Firefox :: Enterprise Policies, defect, P1)

defect

Tracking

()

VERIFIED FIXED
98 Branch
Tracking Status
firefox-esr91 --- verified
firefox96 --- wontfix
firefox97 + verified
firefox98 + verified

People

(Reporter: mkaply, Assigned: mkaply)

References

(Regression)

Details

(Keywords: regression)

Attachments

(1 file)

If you block about:config via policy, then go to the URL and explicitly change the c in config to C, you can view about:config.

This bypasses the autocomplete which forces it to about:config.

I'm going to make sure about:reader does the right thing as well even though doing about:READER?url=https://www.yahoo.com doesn't work - see bug 1750220

Is that a regression? Does it affect ESR?

Flags: needinfo?(mozilla)

Is that a regression?

Yes, but it happened a long time ago (Firefox 84)

Does it affect ESR?

Yes.

Flags: needinfo?(mozilla)
Regressed by: 1559181
Has Regression Range: --- → yes
Pushed by mozilla@kaply.com: https://hg.mozilla.org/integration/autoland/rev/bca9eb24bb0f Block mixed case about URLs in policy. r=Gijs
Regressions: 1750863
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 98 Branch

Set release status flags based on info from the regressing bug 1559181

Flags: in-testsuite+

Comment on attachment 9259123 [details]
Bug 1750221 - Block mixed case about URLs in policy. r?mstriemer,mtigley

ESR Uplift Approval Request

  • If this is not a sec:{high,crit} bug, please state case for ESR consideration: Policy only
  • User impact if declined: User can bypass blocked about pages
  • Fix Landed on Version: 98
  • Risk to taking this patch: Low
  • Why is the change risky/not risky? (and alternatives if risky): Policy, lots of automated tests

Beta/Release Uplift Approval Request

  • User impact if declined: User can bypass blocked about pages
  • Is this code covered by automated tests?: Yes
  • Has the fix been verified in Nightly?: No
  • Needs manual test from QE?: Yes
  • If yes, steps to reproduce: Steps in bug
  • List of other uplifts needed: None
  • Risk to taking this patch: Low
  • Why is the change risky/not risky? (and alternatives if risky): Policy only, lots of automated tests
  • String changes made/needed:
Attachment #9259123 - Flags: approval-mozilla-esr91?
Attachment #9259123 - Flags: approval-mozilla-beta?
Flags: qe-verify+
QA Whiteboard: [qa-triaged]

Comment on attachment 9259123 [details]
Bug 1750221 - Block mixed case about URLs in policy. r?mstriemer,mtigley

Approved for 97.0b6.

Attachment #9259123 - Flags: approval-mozilla-beta? → approval-mozilla-beta+

Comment on attachment 9259123 [details]
Bug 1750221 - Block mixed case about URLs in policy. r?mstriemer,mtigley

Approved for 91.6esr.

Attachment #9259123 - Flags: approval-mozilla-esr91? → approval-mozilla-esr91+

This is verified fixed using Firefox 98.0a1 (BuildID:20220127213627), 97.0b9 (BuildId:20220127193706) and Firefox 91.6.0esr (provided in comment 12) on Windows 10 64bit, macOS 11 & Ubuntu 18.04.

Verified that about pages like about:addons, about:config and about:profiles can no longer be bypassed via mixed cases on Windows 10 64bit (using both policies.json & GPO), Ubuntu 18.04 (via json) & macOS 11 (via json).

Status: RESOLVED → VERIFIED
Flags: qe-verify+
QA Whiteboard: [qa-triaged]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: