git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [BUG] gitweb: XSS vulnerability of RSS feed

From
DNDrew Northup <n1xim.email@gmail.com>
Date
Nov 12, 2012, 18:55 UTC
Message-ID
<CAM9Z-n=6xsC7yiKJ+NU-CxNPxEXWmJzvXLUocgZgWPQnuK6G4Q@mail.gmail.com>
In-Reply-To
<20121111232820.284510@gmx.net>
On Sun, Nov 11, 2012 at 6:28 PM, glpk xypron <xypron.glpk@gmx.de> wrote:
Show 22 quoted lines
> Gitweb can be used to generate an RSS feed.
>
> Arbitrary tags can be inserted into the XML document describing
> the RSS feed by careful construction of the URL.
>
> Example
> http://server/?p=project.git&a=rss&f=</title><script>alert(document.cookie)</script><title>
>
> The generated XML contains
> <script>alert(document.cookie)</script>
>
> Depending on the system used to render the XML this might lead
> to the execution of javascript in the security context of the
> gitweb server pages.
>
> Please, escape all URL parameters.
>
> Version tested:
> gitweb v.1.8.0.dirty with git 1.7.2.5
>
> Best regards
>> Heinrich Schuchardt

Something like this may be useful to defuse the "file" parameter, but I presume a more definitive fix is in order...

diff --git a/gitweb/gitweb.perl b/gitweb/gitweb.perl
index 10ed9e5..af93e65 100755
--- a/gitweb/gitweb.perl
+++ b/gitweb/gitweb.perl
@@ -1447,6 +1447,10 @@ sub validate_pathname {
        if ($input =~ m!\0!) {
                return undef;
        }
+       # No XSS <script></script> inclusions
+       if ($input =~ m!(<script>)(.*)(</script>)!){
+               return undef;
+       }
        return $input;
 }


(I am not a perl god, so this was the lowest hanging fruit.)

If desired I'll fashion this up into a proper patch.
-- 
-Drew Northup
--------------------------------------------------------------
"As opposed to vegetable or mineral error?"
-John Pescatore, SANS NewsBites Vol. 12 Num. 59
Previous: glpk xypronNext: Jeff King
Message 2 of 15 in “[BUG] gitweb: XSS vulnerability of RSS feed”
  1. glpk xypronNov 11, 2012
  2. Drew NorthupNov 12, 2012
  3. Jeff KingNov 12, 2012
  4. Jeff KingNov 12, 2012
  5. Junio C HamanoNov 12, 2012
  6. Jakub NarębskiNov 12, 2012
  7. Jeff KingNov 12, 2012
  8. Drew NorthupNov 13, 2012
  9. Jakub NarębskiNov 13, 2012
  10. KevinNov 13, 2012
  11. Jakub NarębskiNov 13, 2012
  12. Jeff KingNov 13, 2012
  13. Jakub NarębskiNov 13, 2012
  14. Andreas SchwabNov 12, 2012
  15. Pyeron, Jason J CTR (US)Nov 13, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.