Skip to content

Commit 89c8fe9

Browse files
committed
- Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008]
Credits to Oskar Zeino-Mahmalat (Sonar) https://www.sonarsource.com
1 parent 68af7c8 commit 89c8fe9

3 files changed

Lines changed: 21 additions & 5 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@
1515
- Fix infinite loop when parsing malformed Sieve script (#9562)
1616
- Fix bug where imap_conn_option's 'socket' was ignored (#9566)
1717
- Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009]
18+
- Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008]
1819

1920
## Release 1.6.7
2021

‎program/actions/mail/get.php‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -259,6 +259,11 @@ public function run($args = [])
259259
$rcmail->gettext('allow'),
260260
$rcmail->url(array_merge($_GET, ['_safe' => 1]))
261261
);
262+
} else {
263+
// Use strict security policy to make sure no javascript is executed
264+
// TODO: Make the above "blocked resources button" working with strict policy
265+
// TODO: Move this to rcmail_html_page::write()?
266+
header("Content-Security-Policy: script-src 'none'");
262267
}
263268
}
264269

‎program/lib/Roundcube/rcube_output.php‎

Lines changed: 15 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -242,13 +242,20 @@ public function download_headers($filename, $params = [])
242242
$ctype = $params['type'];
243243
}
244244

245-
if ($disposition == 'inline' && stripos($ctype, 'text') === 0) {
246-
$charset = $this->charset;
247-
if (!empty($params['type_charset']) && rcube_charset::is_valid($params['type_charset'])) {
248-
$charset = $params['type_charset'];
245+
// Send unsafe content as plain text
246+
if ($disposition == 'inline') {
247+
if (preg_match('~(javascript|jscript|ecmascript|xml|html|text/)~i', $ctype)) {
248+
$ctype = 'text/plain';
249249
}
250250

251-
$ctype .= "; charset={$charset}";
251+
if (stripos($ctype, 'text') === 0) {
252+
$charset = $this->charset;
253+
if (!empty($params['type_charset']) && rcube_charset::is_valid($params['type_charset'])) {
254+
$charset = $params['type_charset'];
255+
}
256+
257+
$ctype .= "; charset={$charset}";
258+
}
252259
}
253260

254261
if (is_string($filename) && strlen($filename) > 0 && strlen($filename) <= 1024) {
@@ -278,6 +285,9 @@ public function download_headers($filename, $params = [])
278285
header("Content-Length: " . $params['length']);
279286
}
280287

288+
// Use strict security policy to make sure no javascript content is executed
289+
header("Content-Security-Policy: default-src 'none'");
290+
281291
// don't kill the connection if download takes more than 30 sec.
282292
if (!array_key_exists('time_limit', $params)) {
283293
$params['time_limit'] = 3600;

0 commit comments

Comments
 (0)