• 2023 Week 30-32 (from Jul 24)

      Summary
      Using BC UI for creating branches, user can use XSS to read the cookie or create a alert.
      The malformed branch, with XSS name or similar is not created, however the modal can be used to read cookie or extract other information consistently on one place.

      Steps
      1. Login to BC and navigate to a project
      ( Spaces > RestSpace_3 > my_orject_rhpam > master )
      2. There is a hyperlink with text `master` and a dropdown, click it
      3. Pop-up appears where you click Add Branch
      4. Input <img/src/onerror=alert(document.cookie)>
      5. Alert with cookie content is shown

            [RHPAM-4723] Creating a branch via BC UI can lead to XSS

            Marked as Closed for all verified/Release pending issues

            Marek Novotny added a comment - Marked as Closed for all verified/Release pending issues

            dhanak@redhat.com if possible, please make this issue public so we can include the link in the release notes.

            Emily Murphy added a comment - dhanak@redhat.com if possible, please make this issue public so we can include the link in the release notes.

            Fixing assignee to paulovmr as he is the one who submitted fix for this issue.

            Dominik Hanak added a comment - Fixing assignee to paulovmr as he is the one who submitted fix for this issue.

            Verified with 7.13.4.CR1

            Dominik Hanak added a comment - Verified with 7.13.4.CR1

              paulovmr Paulo Rego
              dhanak@redhat.com Dominik Hanak
              Dominik Hanak Dominik Hanak
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: