New issue
Advanced search Search tips

Issue 797665 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Leak REFERER

Reported by jackwill...@gmail.com, Dec 26 2017

Issue description

Components: Blink>SecurityFeature>Referrer
Labels: Needs-Feedback
Can you elaborate on why you believe this demonstrates a security vulnerability?

The Google.com page does not appear to undertake any effort (e.g. by setting ReferrerPolicy) to prevent its URL from being sent as a referrer (which, given that the URL contains nothing sensitive, seems reasonable).
Status: WontFix (was: Unconfirmed)
By default, browsers send the Referer header for each navigation, except in HTTPS->HTTP navigations (to avoid leaking HTTPS-protected data over HTTP). Individual sites can specify a Referrer Policy [1] to override this default. The redirection page in this report does not do so and thus the default behavior is followed.

[1] https://www.w3.org/TR/referrer-policy/
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 5 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment