Closed Bug 771050 Opened 12 years ago Closed 12 years ago

WP Plugin: simple-embed-code

Categories

(mozilla.org :: Security Assurance: Review Request, task)

task
Not set
normal

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: nmaul, Assigned: mfuller)

References

()

Details

(Whiteboard: [completed secreview][start 2012/07/23][start 2012/07/24])

Attachments

(1 file)

Who is/are the point of contact(s) for this review?
Janet Swisher and :jakem

    Please provide a short description of the feature / application (e.g. problem solved, use cases, etc.):
Wordpress plugin for hacks.mozilla.org to allow easy embedding of video, audio, and iframes.

    Please provide links to additional information (e.g. feature page, wiki) if available and not yet included in feature description:
http://wordpress.org/extend/plugins/simple-embed-code/

    Does this request block another bug? If so, please indicate the bug number
Blocks bug 742146

    This review will be scheduled amongst other requested reviews. What is the urgency or needed completion date of this review?
Don't know

    To help prioritize this work request, does this project support a goal specifically listed on this quarter's goal list? If so, which goal?
Don't know

    Please answer the following few questions: (Note: If you are asked to describe anything, 1-2 sentences shall suffice.)
        Does this feature or code change affect Firefox, Thunderbird or any product or service the Mozilla ships to end users?
No
        Are there any portions of the project that interact with 3rd party services?
No
        Will your application/service collect user data? If so, please describe
No
    If you feel something is missing here or you would like to provide other kind of feedback, feel free to do so here (no limits on size):
    Desired Date of review (if known from https://mail.mozilla.com/home/ckoenig@mozilla.com/Security%20Review.html) and whom to invite. 
This is 3rd party code... no need to schedule a review with us.
Whiteboard: [pending secreview] → [pending secreview][triage needed 2012.07.11]
I am willing to take this one on if it can be put on ice for a couple of weeks.
Assignee: nobody → amuntner
Whiteboard: [pending secreview][triage needed 2012.07.11] → [pending secreview][start 2012/07/23][start 2012/07/24]
No hurry, bug 742146 has been waiting 3 months already :-)

Because WordPress allows only Administrators to post privileged elements, over time, we've made more users into admins than we otherwise would. They're all trusted users, but it increases the exposure. This plug-in enables ordinary authors to post privileged elements, so we don't have to make them admins to do that.
Adam, I can take this bug and start on it today. If that's okay with you, feel free to assign it to me.

Matt
good enough for me, assigned to :mfuller
Assignee: amuntner → mfuller
Due Date: 2012-07-06
During the security review of this plugin, an XSS vulnerability was found. I will be contacting the developer of the plugin for an update, or I can provide a recommended fix to someone who will be installing this plugin, but until the issue is corrected, I cannot approve its installation.
Depends on: 771315
My security review is complete but the bug won't be resolved until 771315 is fixed via the developer.

I've attached my full set of notes, but the main points are:

- Fix XSS issue in admin search page.
- Realize that this plugin allows the insertion of additional content types such as scripts, iframes, etc. as well as full inclusions of remote pages. All authors should be instructed not to load scripts or pages from offsite resources unless it is trusted (i.e. a YouTube video would be fine, a JavaScript link from a random third-party would not be).
Attached file Security Review Report
Removing due date since this relies on a third-party dev to fix.
Due Date: 2012-07-06 00:00:00
Bug 771315 is now resolved due to the developer's fixed update. I am marking this review complete as that was the only outstanding concern I had with this plugin. Please proceed to installation.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
Whiteboard: [pending secreview][start 2012/07/23][start 2012/07/24] → [completed secreview][start 2012/07/23][start 2012/07/24]
Blocks: 771568
Status: RESOLVED → VERIFIED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: