GHSA-qm5v-pj64-852j
Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"
Quick fix
GHSA-qm5v-pj64-852j — passbolt/passbolt_api: upgrade to the fixed version with the command below.
composer require passbolt/passbolt_api:^2.11.0Details
### Description A user could create and share a resource with a malicious URI. When the victim opens with menu “Open URI in a new tab” function, the malicious page has access to the window.opener object.
### Impact of issue The newly opened malicious page can for example change the window.opener.location to redirect the user to a phishing page, or call a JavaScript function served by the AppJS on the user behalf for example to try to affect the integrity of the data.
### Fix The code that opens a new window via window.open(); now open the tab with the noopener attribute.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.11.0composer require passbolt/passbolt_api:^2.11.0References
- https://github.com/passbolt/passbolt_api/commit/f568e113beb3134446eda9e66400d28d726ee20d[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/passbolt/passbolt_api/2019-08-07-3.yaml[WEB]
- https://github.com/passbolt/passbolt_api[PACKAGE]
- https://www.passbolt.com/incidents/20190807_multiple_vulnerabilities[WEB]