Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

[Possible] Phishing by Navigating Browser Tabs

Bernardo Joaquín Diaz October 28, 2020

Hello,

I've been reported the next Low vulnerability:

"Open windows with normal hrefs with the tag target="_blank" can modify window.opener.location and replace the parent webpage with something else, even on a different origin. "

It is located on the dropdown menu of the help option up in the nav bar. Could anyone confim me if it has a solution or has been checked?

On the vulnerability it is said that it can be fixed with rel="noopener noreferrer" added to the links to avoid a third party using window.opener.location.assign to exploit this.

 

2 answers

1 accepted

0 votes
Answer accepted
Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
October 31, 2020

Hi Bernardo,

in case the finding matches the definition of vulnerabilities I would not wait and report it to security team as stated in:

https://www.atlassian.com/trust/security/report-a-vulnerability

Cheers,
Daniel

0 votes
Guido Scollo December 13, 2024

Hi Bernardo,

can you tell me if there is an issue opened with this vulnerability, please?

Suggest an answer

Log in or Sign up to answer
TAGS
atlassian, atlassian community, loom ai, atlassian loom ai, loom, atlassian ai, record recaps of meetings, meeting recaps, loom recaps, share meeting recaps,

Loom’s guide to great meetings 📹

Join us to learn how your team can stay fully engaged in meetings without worrying about writing everything down. Dive into Loom's newest feature, Loom AI for meetings, which automatically takes notes and tracks action items.

Register today!
AUG Leaders

Atlassian Community Events