Skip to content

JS: Add files as a source for js/xss-through-dom#8678

Merged
erik-krogh merged 2 commits into
github:mainfrom
erik-krogh:fileSource
Apr 20, 2022
Merged

JS: Add files as a source for js/xss-through-dom#8678
erik-krogh merged 2 commits into
github:mainfrom
erik-krogh:fileSource

Conversation

@erik-krogh
Copy link
Copy Markdown
Contributor

@erik-krogh erik-krogh commented Apr 6, 2022

Recognizes the source for CVE-2021-32622

Also adds a taint-step for URL.createObjectURL, also inspired by the same CVE.
I've just added the step to the js/xss-throgh-dom.
The step is only relevant for XSS, and I think it's mostly relevant for js/xss-throgh-dom, so I'm just putting it there for now.

Evaluation looks fine. One new result that looks like a TP.

@github-actions github-actions Bot added the JS label Apr 6, 2022
@erik-krogh erik-krogh marked this pull request as ready for review April 6, 2022 19:27
@erik-krogh erik-krogh requested a review from a team as a code owner April 6, 2022 19:27
@erik-krogh erik-krogh added the no-change-note-required This PR does not need a change note label Apr 20, 2022
@erik-krogh erik-krogh merged commit 10130ee into github:main Apr 20, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

JS no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants