cross-browser CORS bypass
Categories
(Core :: DOM: Networking, defect)
Tracking
()
People
(Reporter: martin.oneal, Unassigned)
Details
(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
An oversight in the whatwg standard for fetch allowed the CORS restrictions that limit the methods to be bypassed. Amongst other things, this allowed Cross Sitew Tracing (XST) to be brought back from the dead.
The bug has been fixed at the whatwg level now, and has had patches applied to all the common browsers.
the firefox bug is here: https://bugzilla.mozilla.org/show_bug.cgi?id=1790311
Updated•2 years ago
|
Comment 1•2 years ago
|
||
I'm sorry, I don't understand what you are reporting here. Is this is distinct issue from bug 1790311? Are you saying that bug 1790311 is incomplete or that there is some other issue? Thanks.
ah, looks like a misunderstanding. I was looking to register the issue for a bug bounty, and the web site said I needed to fill in a form, which generated a second ticket. Probably needs ammending for clarity!
It's a duplicate so good to close.
Comment 3•2 years ago
|
||
Thanks for the explanation.
Updated•2 years ago
|
Updated•2 years ago
|
Updated•9 months ago
|
Description
•