Closed
Bug 666302
Opened 14 years ago
Closed 14 years ago
Reflected XSS in TBPL
Categories
(Tree Management Graveyard :: TBPL, defect)
Tree Management Graveyard
TBPL
Tracking
(Not tracked)
VERIFIED
FIXED
People
(Reporter: ygjb, Unassigned)
References
()
Details
(Keywords: wsec-xss, Whiteboard: [infrasec:xss][ws:high])
Reported by ignatio2007@gmail.com
Issue
There is a reflected XSS vulnerability in the tree parameter in tbpl.mozilla.org.
Steps to Reproduce
1. Navigate to the URL above.
Recommendation
Perform appropriate input validation on parameters, and use output encoding as appropriate for the application.
Reporter | ||
Updated•14 years ago
|
Whiteboard: [infrasec:xss][ws:critical]
Comment 2•14 years ago
|
||
Thanks for the report.
This bug should be fixed by http://hg.mozilla.org/users/mstange_themasta.com/tbpl-pending-infrasec-review/rev/9980c25399a1 and http://hg.mozilla.org/users/mstange_themasta.com/tbpl-pending-infrasec-review/rev/10b06acaa3a2
These fixes haven't been deployed to tbpl.mozilla.org yet, but they can be tested on http://tbpl.swatinem.de/
We'll deploy them to tbpl.mozilla.org (along with all the rest from http://hg.mozilla.org/users/mstange_themasta.com/tbpl-pending-infrasec-review/ ) once the security review in bug 661365 is confirmed to be finished.
Depends on: 665787
Comment 3•14 years ago
|
||
661365 has been verified fix. anything else we need for this one?
Comment 4•14 years ago
|
||
Nothing, the fix just needs to be deployed.
Reporter | ||
Updated•14 years ago
|
Reporter | ||
Updated•14 years ago
|
Whiteboard: [infrasec:xss][ws:critical] → [infrasec:xss][ws:high]
Comment 7•14 years ago
|
||
Issue is resolved.
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Updated•14 years ago
|
Group: webtools-security
Status: RESOLVED → VERIFIED
Reporter | ||
Comment 8•12 years ago
|
||
Adding keywords to bugs for metrics, no action required. Sorry about bugmail spam.
Keywords: wsec-xss
Assignee | ||
Updated•11 years ago
|
Product: Webtools → Tree Management
Assignee | ||
Updated•10 years ago
|
Product: Tree Management → Tree Management Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•