Uploaded image for project: 'Red Hat Process Automation Manager'
  1. Red Hat Process Automation Manager
  2. RHPAM-4723

Creating a branch via BC UI can lead to XSS

XMLWordPrintable

    • 2023 Week 30-32 (from Jul 24)

      Summary
      Using BC UI for creating branches, user can use XSS to read the cookie or create a alert.
      The malformed branch, with XSS name or similar is not created, however the modal can be used to read cookie or extract other information consistently on one place.

      Steps
      1. Login to BC and navigate to a project
      ( Spaces > RestSpace_3 > my_orject_rhpam > master )
      2. There is a hyperlink with text `master` and a dropdown, click it
      3. Pop-up appears where you click Add Branch
      4. Input <img/src/onerror=alert(document.cookie)>
      5. Alert with cookie content is shown

              paulovmr Paulo Rego
              dhanak@redhat.com Dominik Hanak
              Dominik Hanak Dominik Hanak
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: