Closed Bug 1898210 Opened 5 months ago Closed 5 months ago

Sensitive informations, supposed to be hidden, can be revealed on PDF saved using draw feature on PDF Editor (Firefox)

Categories

(Firefox :: Security, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1898195

People

(Reporter: renatoyamane, Unassigned)

References

()

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(1 file)

Attached file PDF_edited_firefox.pdf

Steps to reproduce:

  1. Open a PDF file on Firefox 126.0 (Windows 11);

  2. Use the draw feature to edit the PDF, to hide a sensitive information;
    https://www.mozilla.org/en-GB/firefox/features/pdf-editor/

  3. Save it;

  4. Open it again, use CTRL+A to select the content of the PDF, then copy the text and paste it in somewhere (for example: notepad).

You will notice the text, supposed to be hidden, can be revealed when you paste the content.

Use the PDF attached to reproduce the problem.

  • Expected results:

The text behind the draw/brush should not be revealed. Firefox should MERGE all layers before saving the PDF.
This is a security issue, because users can have sensitive informations revealed.

Flags: sec-bounty?

Not sure why you reported this a second time?

Status: UNCONFIRMED → RESOLVED
Closed: 5 months ago
Duplicate of bug: 1898195
Resolution: --- → DUPLICATE

(In reply to :Gijs (he/him) from comment #1)

Not sure why you reported this a second time?
*** This bug has been marked as a duplicate of bug 1898195 ***

I reported also on the Bug Bounty Program, but I didn't know it could arrive on the same place. Sorry.
Please conside adding the sec-bounty tag on Bug 1898195, if you think it is relevant.
Thanks

Group: firefox-core-security
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: