diff options
author | Simon Green <sgreen@redhat.com> | 2014-07-24 17:26:23 +0000 |
---|---|---|
committer | David Lawrence <dkl@mozilla.com> | 2014-07-24 17:26:23 +0000 |
commit | f0760dd1c4ce87bf7fa5f8ce70cc7c8a45041a6b (patch) | |
tree | 9806496e071f5b25004214bb26c33ceadcd3fdab | |
parent | Bump version to 4.2.10 (diff) | |
download | bugzilla-f0760dd1c4ce87bf7fa5f8ce70cc7c8a45041a6b.tar.gz bugzilla-f0760dd1c4ce87bf7fa5f8ce70cc7c8a45041a6b.tar.bz2 bugzilla-f0760dd1c4ce87bf7fa5f8ce70cc7c8a45041a6b.zip |
Bug 1036213 - (CVE-2014-1546) add '/**/' before jsonrpc.cgi callback to avoid swf content type sniff vulnerability
r=glob,a=sgreen
-rw-r--r-- | Bugzilla/WebService/Server/JSONRPC.pm | 5 |
1 files changed, 3 insertions, 2 deletions
diff --git a/Bugzilla/WebService/Server/JSONRPC.pm b/Bugzilla/WebService/Server/JSONRPC.pm index cec1c29ea..373aa4fe0 100644 --- a/Bugzilla/WebService/Server/JSONRPC.pm +++ b/Bugzilla/WebService/Server/JSONRPC.pm @@ -91,8 +91,9 @@ sub response { # Implement JSONP. if (my $callback = $self->_bz_callback) { my $content = $response->content; - $response->content("$callback($content)"); - + # Prepend the JSONP response with /**/ in order to protect + # against possible encoding attacks (e.g., affecting Flash). + $response->content("/**/$callback($content)"); } # Use $cgi->header properly instead of just printing text directly. |