git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [BUG] gitweb: XSS vulnerability of RSS feed

From
Jakub Narębski <jnareb@gmail.com>
Date
Nov 13, 2012, 17:22 UTC
Message-ID
<CANQwDwcNXPhA3Qe2K_GLuh3F8DObDQ+Wn_PHhTkJqM+4D+SK0w@mail.gmail.com>
In-Reply-To
<20121113170452.GE20361@sigill.intra.peff.net>
On Tue, Nov 13, 2012 at 6:04 PM, Jeff King <peff@peff.net> wrote:
> On Tue, Nov 13, 2012 at 09:44:06AM -0500, Drew Northup wrote:
Show 7 quoted lines
>> Besides, inserting one call to esc_html only fixes one attack path. I
>> didn't look to see if all others were already covered.
>
> Properly quoting output is something that the web framework should do
> for you. gitweb uses CGI.pm, which does help with that, but we do not
> use it consistently. If there are other problematic areas, I think the
> best path forward is to use our framework more.

Well, calling CGI.pm a _framework_ is overly generous, but it does include some HTML generation subroutines / methods, and gitweb makes use of them, especially $cgi->a() for links.

But it cannot help in this case, because here we are generating XML: RSS or Atom feed. There was proposal some time ago to switch to using XML::FeedPP or XML::Atom::Feed + XML::RSS::Feed for feed generation.

Perhaps it is high time to switch to some Perl web (micro)framework, like Dancer, Mojolicious or Catalyst... but not requiring extra modules has its advantages (and there always exist Gitalist).

-- 
Jakub Narebski
Previous: Jeff KingNext: Andreas Schwab
Message 13 of 15 in “[BUG] gitweb: XSS vulnerability of RSS feed”
  1. glpk xypronNov 11, 2012
  2. Drew NorthupNov 12, 2012
  3. Jeff KingNov 12, 2012
  4. Jeff KingNov 12, 2012
  5. Junio C HamanoNov 12, 2012
  6. Jakub NarębskiNov 12, 2012
  7. Jeff KingNov 12, 2012
  8. Drew NorthupNov 13, 2012
  9. Jakub NarębskiNov 13, 2012
  10. KevinNov 13, 2012
  11. Jakub NarębskiNov 13, 2012
  12. Jeff KingNov 13, 2012
  13. Jakub NarębskiNov 13, 2012
  14. Andreas SchwabNov 12, 2012
  15. Pyeron, Jason J CTR (US)Nov 13, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.