#30070 closed Bug (fixed)
Content spoofing possiblity in default 404 page
| Reported by: | tasn | Owned by: | nobody |
|---|---|---|---|
| Component: | Core (Other) | Version: | 1.11 |
| Severity: | Release blocker | Keywords: | |
| Cc: | Triage Stage: | Accepted | |
| Has patch: | yes | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | yes |
| Easy pickings: | no | UI/UX: | no |
Description
A maliciously crafted URL can be reflected back to the user so that the user sees a 404 page with the attacker's content that may be interpreted as originating from the trusted site.
PR with details.
Change History (5)
comment:1 by , 7 years ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
comment:5 by , 7 years ago
If it helps anyone, https://gist.github.com/lamby/0a816cfddfd3824bc42093a37ef9cd41/raw is a version for 1.7.11 (out of LTS support).
Note:
See TracTickets
for help on using tickets.
In 1ecc0a39: