You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Partially resolved in PR #5157. The issue was fixed by limiting new navigations for the localhost and lisk.com hostnames. However, the protocol of the URLis not checked, so URLs such as smb://localhost incorrectly pass this check. We recommend also ensuring that the protocol is https. Furthermore, the catch block of handleRedirect function does not have a call to e.preventDefault(), which may allow other bypasses (we did not attempt to exploit this).
The text was updated successfully, but these errors were encountered:
ManuGowda
changed the title
TOB-LISK-56: Electron app does not validate URLs on new windows and navigation
Electron app does not validate URLs on new windows and navigation
Sep 4, 2023
Actual behavior
Partially resolved in PR #5157. The issue was fixed by limiting new navigations for the localhost and lisk.com hostnames. However, the protocol of the URLis not checked, so URLs such as smb://localhost incorrectly pass this check. We recommend also ensuring that the protocol is https. Furthermore, the catch block of handleRedirect function does not have a call to e.preventDefault(), which may allow other bypasses (we did not attempt to exploit this).
The text was updated successfully, but these errors were encountered: