Closed Bug 1962084 Opened 1 year ago Closed 11 months ago

Ship escaping of "<" and ">" in attributes

Categories

(Core :: DOM: Core & HTML, task)

task

Tracking

()

RESOLVED FIXED
140 Branch
Tracking Status
relnote-firefox --- 140+
firefox140 --- fixed

People

(Reporter: tschuster, Assigned: tschuster)

References

Details

(Keywords: dev-doc-complete, sec-want, Whiteboard: [adv-main140-])

Attachments

(1 file)

No description provided.
Pushed by tschuster@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/513d59a1da84 Ship escaping of "<" and ">" in attributes. r=zcorpan,hsivonen,dom-core
Keywords: dev-doc-needed
Status: NEW → RESOLVED
Closed: 11 months ago
Resolution: --- → FIXED
Target Milestone: --- → 140 Branch

Tom, could you consider nominating this for a release note? (Process info)

Flags: needinfo?(tschuster)

FF140 MDN docs for this can be tracked on https://github.com/mdn/content/issues/39628

Release Note Request (optional, but appreciated)
[Why is this notable]: Prevents certain mXSS attacks and changes behavior
[Affects Firefox for Android]: Yes
[Suggested wording]: Firefox will now escape less-than (<) and greater-than (>) symbols when serializing HTML attributes, making certain mXSS attacks on websites more difficult.
[Links (documentation, blog post, etc)]: https://github.com/whatwg/html/issues/6235 (Maybe someone knows of a blog post?)

relnote-firefox: --- → ?
Flags: needinfo?(tschuster)

Thanks, added to the Fx140 nightly release notes, please allow 30 minutes for the site to update.
Keeping the relnote-firefox flag as ? to keep it on the radar for inclusion in the final Fx140 release notes.

QA Whiteboard: [qa-triage-done-c141/b140]
Whiteboard: [adv-main140-]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: