HIGH8.8
GHSA-mr5m-2385-2vcp
xdlocalstorage does not verify request origin
Details
An issue was discovered in xdLocalStorage through 2.0.5. The `postData()` function in `xdLocalStoragePostMessageApi.js` specifies the wildcard (`*`) as the targetOrigin when calling the `postMessage()` function on the parent object. Therefore any domain can load the application hosting the "magical iframe" and receive the messages that the "magical iframe" sends.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/xdlocalstorage
Introduced in:
0No fixed version published yet for xdlocalstorage (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-11610[ADVISORY]
- https://github.com/ofirdagan/cross-domain-local-storage/issues/17[WEB]
- https://github.com/ofirdagan/cross-domain-local-storage/pull/19[WEB]
- https://github.com/ofirdagan/cross-domain-local-storage[PACKAGE]
- https://grimhacker.com/exploiting-xdlocalstorage-localstorage-and-postmessage/#Missing-TargetOrigin-Magic-iframe[WEB]