You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Kevin Reid edited this page Apr 16, 2015
·
1 revision
(legacy summary: Security Advisory 19 October 2009)
Caja Security Advisory 19-October-2009
Revision 3652 introduced changes to allow iframe shims to work
around layout problems in older browsers, but did not update the
default HTML schemas to block uses of iframes to load code.
Impact
These vulnerabilities allow attacking sandboxed code to completely
bypass all Caja's protections if the container is using a version of
the HTML schemas between revision 3652 and 3810, and is
using a URI policy that does not reject or block by proxying URLs where
the mime-type is text/html.
Advice
Do one of the following:
Best: Upgrade to a version of Caja at or after 3810.