-
Notifications
You must be signed in to change notification settings - Fork 1.8k
Experimental query: ClipboardBasedXss #6498
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the submission! Just a quick comment for now; a proper review will come later.
javascript/ql/src/experimental/Security/CWE-079/ClipboardXss.ql
Outdated
Show resolved
Hide resolved
Co-authored-by: Asger F <asgerf@github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks again for the submission @bananabr 👍
We'd be happy to merge the query like this. In the future we will most likely move the clipboard source into the js/xss-through-dom query.
javascript/ql/src/experimental/Security/CWE-079/ClipboardXss.ql
Outdated
Show resolved
Hide resolved
Typo fix Co-authored-by: Asger F <asgerf@github.com>
Simplifies query to improve performance by removing unnecessary results.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM 👍
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- [ ]
This query looks for potential DomBasedXSS vulnerabilities whose source is the clipboard API. This source is not currently covered by the official XSS queries.