Mozilla Foundation Security Advisory 2008-10
URL token stealing via stylesheet redirect
- Announced
- February 7, 2008
- Reporter
- Martin Straka
- Impact
- Low
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 2.0.0.12
- SeaMonkey 1.1.8
Description
Security researcher Martin Straka reported
that Gecko-based browsers update the .href
property of stylesheet
DOM nodes to reflect the final URI of the stylesheet after following
any 302 redirects (much as the document.location property is updated).
This differs from other browsers and could potentially reveal sensitive
URL parameters, such as those used by Single-signon sytems, to scripts
on the page.
Workaround
Disable JavaScript until a version containing these fixes can be installed.