New issue
Advanced search Search tips

Issue 736339 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: bug with exposed js

Reported by gabrielm...@gmail.com, Jun 23 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
You have exposed css and Javascript here:


1) search in Google  Shopping "teva sandals men" 

2) click the black sandals that say they're from Nordstrom rack. 

3) click on more details, or notice already that css is leaked. Clicking on more details exposes information about endpoints and just raw Javascript. 

VERSION
Chrome Version: [idk] + [stable]
Operating System: [Android] 

REPRODUCTION CASE

1) search in Google  Shopping "teva sandals men" 

2) click the black sandals that say they're from Nordstrom rack. 

3) click on more details, or notice already that css is leaked. Clicking on more details exposes information about endpoints and just raw Javascript. 


FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
Status: WontFix (was: Unconfirmed)
This isn't a security bug (JavaScript and CSS are freely available for viewing).

This is a functional issue with that website, and reproduces in all browsers. I've filed a bug against the Google Shopping site.
FunctionalBug.png
253 KB View Download
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 30 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment