Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); SECURITY: FIX unintended Email protocol resolution by Pranav-yadav · Pull Request #3759 · react/react-native-website · GitHub
Skip to content

SECURITY: FIX unintended Email protocol resolution - #3759

Merged
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution
Jun 13, 2023
Merged

SECURITY: FIX unintended Email protocol resolution#3759
cortinico merged 1 commit into
react:mainfrom
Pranav-yadav:Pranav-yadav/security-fix-email-protocol-resolution

Conversation

@Pranav-yadav

@Pranav-yadavPranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
Contributor

Summary

Fixes#3758

Wherever we've specified the package versions explicitly and haven't enclosed them in the inline-code-block (`) or multiline-code-block (```) they are resolved as an email protocol (address), which is unintended and is a primary security concern.

This diff updates such occurrences to enclose them in inline code blocks and of course some code formatting touchups 😇

Changelog:

[SECURITY]: FIX unintended Email protocol resolution

Changes

BeforeAfter
imageimage

P.S.: Came across this when working on #3732

@netlify

netlifyBot commented Jun 13, 2023

Copy link
Copy Markdown

Deploy Preview for react-native ready!

NameLink
🔨 Latest commit5db19b8
🔍 Latest deploy loghttps://app.netlify.com/sites/react-native/deploys/6487fe2defa72800084c526a
😎 Deploy Previewhttps://deploy-preview-3759--react-native.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@Pranav-yadav

Pranav-yadav commented Jun 13, 2023

Copy link
Copy Markdown
ContributorAuthor

@cortinico We must backport this change as it's a security concern 🚨.
Lmk, so I can proceed with backporting this (to almost all versions)? 👍

@Simek

Copy link
Copy Markdown
Collaborator

It's not a high security risk, but since the changes are quite simple, it would be nice if you can backport them. 🙂

@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

May not be a high-security issue but, a similar email protocol resolution and domain resolution for .zip files hosted on GitHub[dot]com have been (being) exploited recently.

Since it's only email resolution, and these instances don't make up valid email addresses they are of "low" security concerns. 👍

P.S.: If it was a "high" security concern (vulnerability) I would've reported it privately :)

--

Sure 🙂.

@cortinicocortinico left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for reporting this @Pranav-yadav
and yes let's backport it

@cortinico
cortinico merged commit 90e0d84 into react:mainJun 13, 2023
@Pranav-yadav

Copy link
Copy Markdown
ContributorAuthor

Welcome!
Sure, will open a PR(s) whenever I get some time. 👍

@Pranav-yadav
Pranav-yadav deleted the Pranav-yadav/security-fix-email-protocol-resolution branch June 13, 2023 17:07
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY: Unintended Email protocol resolution for package versions

4 participants

@Pranav-yadav@Simek@cortinico@facebook-github-bot