Skip to content

Conversation

@gcampbell
Copy link
Contributor

Adds a comment before JSONP callbacks. See
the reporter's blog post and the CVE for more information on the vulnerability.

Adds a comment before JSONP callbacks. See
http://miki.it/blog/2014/7/8/abusing-jsonp-with-rosetta-flash/ for more
details on the exploit in question.
@chancancode
Copy link
Member

👍 @tenderlove @rafaelfranca ?

@chancancode
Copy link
Member

(I believe this requires #16026 to work correctly in all cases, which is only in master afaik)

@tenderlove
Copy link
Member

LGTM, I'll merge it.

@tenderlove tenderlove merged commit 4003a5b into rails:master Jul 10, 2014
mehlah added a commit to mehlah/active_model_serializers that referenced this pull request Mar 30, 2015
Since Rails 4.0.10, it prepends a JS comment to JSONP callbacks,
to address CVE-2014-4671.
Introduced in Rails at rails/rails#16109
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants