VDB
Sign up
MEDIUM5.5

GHSA-qm5v-pj64-852j

Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"

Quick fix

GHSA-qm5v-pj64-852j — passbolt/passbolt_api: upgrade to the fixed version with the command below.

composer require passbolt/passbolt_api:^2.11.0

Details

### Description A user could create and share a resource with a malicious URI. When the victim opens with menu “Open URI in a new tab” function, the malicious page has access to the window.opener object.

### Impact of issue The newly opened malicious page can for example change the window.opener.location to redirect the user to a phishing page, or call a JavaScript function served by the AppJS on the user behalf for example to try to affect the integrity of the data.

### Fix The code that opens a new window via window.open(); now open the tab with the noopener attribute.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/passbolt/passbolt_api
Introduced in: 0Fixed in: 2.11.0
Fixcomposer require passbolt/passbolt_api:^2.11.0

References