Closed
Bug 1900648
Opened 1 year ago
Closed 2 months ago
XSLT error messages can leak browser UI language
Categories
(Core :: XSLT, defect)
Core
XSLT
Tracking
()
RESOLVED
FIXED
140 Branch
Tracking | Status | |
---|---|---|
firefox140 | --- | fixed |
People
(Reporter: ma1, Assigned: pierov)
References
(Blocks 2 open bugs)
Details
(Whiteboard: [tor 42288][fingerprinting])
Attachments
(1 file, 2 obsolete files)
This is https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42288 in Tor Browser.
Actual browser UI locale can be inferred by examining the error message for a failed XSLT.
Updated•1 year ago
|
Severity: -- → S3
Component: DOM: Core & HTML → XSLT
Comment 1•1 year ago
|
||
Originally Tor 42288: https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42288
Updated•1 year ago
|
Assignee: nobody → manuel
Status: NEW → ASSIGNED
Updated•4 months ago
|
Blocks: tor-uplift-esr140
Updated•4 months ago
|
Assignee | ||
Comment 2•3 months ago
|
||
I'm taking this Bug (I've already talked about it with Manuel).
Assignee: manuel → pierov
Assignee | ||
Comment 3•3 months ago
|
||
Updated•3 months ago
|
Attachment #9406649 -
Attachment is obsolete: true
Assignee | ||
Comment 4•3 months ago
|
||
Depends on D245695
Comment 5•3 months ago
|
||
Comment on attachment 9479317 [details]
Bug 1900648 - Part 2: Remove nsStringBundleService::FormatStatusMessage. r?#xpcom-reviewers
Revision D245696 was moved to bug 1959147. Setting attachment 9479317 [details] to obsolete.
Attachment #9479317 -
Attachment is obsolete: true
Pushed by enordin@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/b576f6dedd29
Allow language spoofing in XSLT status messages. r=platform-i18n-reviewers,dom-core,farre,nordzilla
Comment 7•2 months ago
|
||
bugherder |
Status: ASSIGNED → RESOLVED
Closed: 2 months ago
status-firefox140:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 140 Branch
Updated•2 months ago
|
QA Whiteboard: [qa-triage-done-c141/b140]
You need to log in
before you can comment on or make changes to this bug.
Description
•