`EventSource` in Web Workers bypasses the `connect-src` CSP directive
Categories
(Core :: DOM: Workers, defect)
Tracking
()
People
(Reporter: lebr0nli, Assigned: tschuster)
Details
(Keywords: csectype-priv-escalation, reporter-external, sec-moderate, Whiteboard: [client-bounty-form][adv-main151+][adv-esr140.11+])
Attachments
(3 files)
VULNERABILITY DETAILS
CSP is not properly enforced when instantiating an EventSource within a Web Worker. This allows an attacker to bypass the restrictive connect-src directive and establish connections to arbitrary URLs with EventSource.
VERSION
Firefox Version: 149.0.2 stable
The vulnerability is also present in Firefox 151.0a1 nightly
REPRODUCTION CASE
Steps to reproduce
- Run the attached
server.pywithpython3 server.pyto start the local server. - Navigate to either
http://127.0.0.1:1337/?bloborhttp://127.0.0.1:1337/?worker.jsin the browser. This will trigger the page to spawn a Web Worker using either a Blob URL or theworker.jsscript. - The worker will attempt to establish an
EventSourceconnection tohttp://127.0.0.1:1337/bypass?bloborhttp://127.0.0.1:1337/bypass?worker.js.
Expected results
The connection should be blocked by the connect-src 'none' CSP.
Actual results
The connection is successfully established.
CREDIT INFORMATION
Reporter credit: lebr0nli of National Yang Ming Chiao Tung University, Dept. of CS, Security and Systems Lab.
Updated•5 months ago
|
| Assignee | ||
Comment 1•5 months ago
|
||
I believe this is another instance of a channel being created without an appropriate ClientInfo being passed: https://searchfox.org/firefox-main/rev/6925ce3cf2987bec22cae8a32e1e8a57e49efd3b/dom/base/EventSource.cpp#1038-1046
| Assignee | ||
Updated•5 months ago
|
| Assignee | ||
Comment 2•5 months ago
|
||
Updated•5 months ago
|
Updated•5 months ago
|
| Assignee | ||
Updated•5 months ago
|
Comment 4•5 months ago
|
||
Comment 5•5 months ago
|
||
Please nominate this for ESR140 uplift when you have a chance.
Comment 6•5 months ago
|
||
firefox-esr140 Uplift Approval Request
- User impact if declined/Reason for urgency: A web security feature CSP could be bypassed and unexpected requests could happen.
- Code covered by automated testing?: no
- Fix verified in Nightly?: yes
- Needs manual QE testing?: no
- Steps to reproduce for manual QE testing:
- Risk associated with taking this patch: low
- Explanation of risk level: Simple and the normal tests for EventSource in Worker continue to pass.
- String changes made/needed?: no
- Is Android affected?: yes
| Assignee | ||
Comment 7•5 months ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D293841
| Assignee | ||
Updated•5 months ago
|
Updated•5 months ago
|
Updated•5 months ago
|
Updated•5 months ago
|
Updated•5 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Updated•1 month ago
|
Description
•