Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

XSS/RCE vulnerability #145

Open
MCOffSec opened this issue Jul 7, 2020 · 8 comments
Open

XSS/RCE vulnerability #145

MCOffSec opened this issue Jul 7, 2020 · 8 comments
Labels

Comments

@MCOffSec
Copy link

MCOffSec commented Jul 7, 2020

During testing of this app I've discovered an XSS flaw that can lead to RCE. Is there a secure/[private place I can post details of the issue?

@jgadsden
Copy link
Collaborator

jgadsden commented Jul 7, 2020

Thanks @MCOffSec for doing this, it is appreciated. Just checking that you mean specifically the desktop application and not the web application at https://github.com/OWASP/threat-dragon ?

For both repos you can email [email protected] using the PGP key at the bottom of the README.md file in either repo

Thanks again, Jon

@jgadsden jgadsden added the bug label Jul 7, 2020
@MCOffSec
Copy link
Author

just checking you received the details via the Flowcrypt page?

@jgadsden
Copy link
Collaborator

@mike-goodwin should have received it? Mike can you confirm?

@jgadsden
Copy link
Collaborator

Hello @MCOffSec - can you give an idea (without disclosure) of how severe this vuln is? Is it exploitable within the desktop application, or is it more targeted towards the online web app at https://github.com/OWASP/threat-dragon ?

@MCOffSec
Copy link
Author

Sure, it impacts the desktop version of the application and requires the user to load a maliciously crafted file in the app then click a commonly used button within the tool.

@jgadsden
Copy link
Collaborator

OK, thanks @MCOffSec , understood. Do you have a fix for this? We are about to release version 1.3 - something like early August, so it would be good to have a fix in place. Many thanks, Jon

@jgadsden
Copy link
Collaborator

This TD repo was migrated to the OWASP organisation repo at https://github.com/OWASP/threat-dragon-desktop/issues . I can duplicate this issue there, where the fix will be applied, or do you want to raise this issue in that repo? You get github credit if you do :-)

@MCOffSec
Copy link
Author

I can raise it there, its not a problem :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants