mirror of
https://github.com/ArchiveBox/ArchiveBox.git
synced 2026-04-25 09:06:02 +03:00
[GH-ISSUE #772] Private Disclosure #488
Labels
No labels
expected: maybe someday
expected: next release
expected: release after next
expected: unlikely unless contributed
good first ticket
help wanted
pull-request
scope: all users
scope: windows users
size: easy
size: hard
size: medium
size: medium
status: backlog
status: blocked
status: done
status: idea-phase
status: needs followup
status: wip
status: wontfix
touches: API/CLI/Spec
touches: configuration
touches: data/schema/architecture
touches: dependencies/packaging
touches: docs
touches: js
touches: views/replayers/html/css
why: correctness
why: functionality
why: performance
why: security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/ArchiveBox#488
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @omriinbar on GitHub (Jun 22, 2021).
Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/772
Hello, do you have an email for private disclosure?
@pirate commented on GitHub (Jun 22, 2021):
https://sweeting.me/#contact watch the canvas background after ~3sec
What's the category of the vuln? XSS/RCE/etc.?
@omriinbar commented on GitHub (Jun 24, 2021):
XSS leading to admin account creation
@pirate commented on GitHub (Jun 24, 2021):
Ok, that's already a known vuln with fix work in progress, see here: #239
https://github.com/ArchiveBox/ArchiveBox#security-risks-of-viewing-archived-js