Uploaded image for project: 'Kogito'
  1. Kogito
  2. KOGITO-9017

Sonar reports cross-origin vulnerabilities

    XMLWordPrintable

Details

    • Quality Risk
    • Resolution: Done
    • Major
    • 1.40.0.Final
    • 1.36.0.Final
    • Runtime Tooling
    • None

    Description

      Sonar check reports vulnerable code constructs when using window.postMessage calls with `*` as targetOrigin.

      The origin specification should be changed to reflect the env of deployment, i.e. specific URL.

      Attachments

        Issue Links

          Activity

            People

              jstastny@redhat.com Jan Stastny
              jstastny@redhat.com Jan Stastny
              Barbora Siskova Barbora Siskova
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: