Uploaded image for project: 'Red Hat Process Automation Manager'
  1. Red Hat Process Automation Manager
  2. RHPAM-4723

Creating a branch via BC UI can lead to XSS

    XMLWordPrintable

Details

    • 2023 Week 30-32 (from Jul 24)

    Description

      Summary
      Using BC UI for creating branches, user can use XSS to read the cookie or create a alert.
      The malformed branch, with XSS name or similar is not created, however the modal can be used to read cookie or extract other information consistently on one place.

      Steps
      1. Login to BC and navigate to a project
      ( Spaces > RestSpace_3 > my_orject_rhpam > master )
      2. There is a hyperlink with text `master` and a dropdown, click it
      3. Pop-up appears where you click Add Branch
      4. Input <img/src/onerror=alert(document.cookie)>
      5. Alert with cookie content is shown

      Attachments

        Activity

          People

            paulovmr Paulo Rego
            dhanak@redhat.com Dominik Hanak
            Dominik Hanak Dominik Hanak
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: