React Developer Tools extension Improper Authorization vulnerability
Moderate severity
GitHub Reviewed
Published
Oct 19, 2023
to the GitHub Advisory Database
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Oct 19, 2023
Published to the GitHub Advisory Database
Oct 19, 2023
Reviewed
Oct 20, 2023
Last updated
Sep 12, 2024
The React Developer Tools extension registers a message listener with window.addEventListener('message', ) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not validated or sanitised before it is fetched, thus allowing a malicious web page to arbitrarily fetch URL’s via the victim's browser.
References