[IMP] Prevent reverse tabnabbing in plaintext2html, linkify, _makeLink

These functions convert plain text links into clickable hyperlinks.
These open in new tabs but did not have the "noreferrer noopener" rel
attributes, which made them susceptible to reverse tabnabbing.

A lot of attack vectors were available to unregistered, uninvited
anonymous users and presented a significant phishing threat (such as
posting links in the instant-chat, through a mail-alias, in a forum post
or in a twitter post) and leading the operator to believe he had been
disconnected from odoo in the original tab, prompting them to enter
their credentials.

while these three places will add the noreferrer and noopener attributes
on the anchor tags generated by them, there are still many places that
create hyperlinks without the use of these functions, although most of
them are static links, they still represent a transitive security
vulnerability to the linked sites.

There are also a few modules and widgets that roll out their own links
or open new tabs unsafely using window.open(), these will need to be
patched separately.

closes odoo/odoo#37591

Signed-off-by: Olivier Dony (odo) <odo@openerp.com>
This commit is contained in:
Samuel Degueldre
2019-10-01 08:24:59 +00:00
parent e121bacbd0
commit 74e23b2e2b
3 changed files with 5 additions and 1 deletions
+3
View File
@@ -33,6 +33,9 @@ function linkify(text, attrs) {
if (attrs.target === undefined) {
attrs.target = '_blank';
}
if (attrs.target === '_blank') {
attrs.rel = 'noreferrer noopener';
}
attrs = _.map(attrs, function (value, key) {
return key + '="' + _.escape(value) + '"';
}).join(' ');
@@ -74,6 +74,7 @@ publicWidget.registry.twitter = publicWidget.Widget.extend({
text: text,
href: url,
target: '_blank',
rel: 'noreferrer noopener',
});
return c.prop('outerHTML');
}
+1 -1
View File
@@ -261,7 +261,7 @@ def html_keep_url(text):
link_tags = re.compile(r"""(?<!["'])((ftp|http|https):\/\/(\w+:{0,1}\w*@)?([^\s<"']+)(:[0-9]+)?(\/|\/([^\s<"']))?)(?![^\s<"']*["']|[^\s<"']*</a>)""")
for item in re.finditer(link_tags, text):
final += text[idx:item.start()]
final += '<a href="%s" target="_blank">%s</a>' % (item.group(0), item.group(0))
final += '<a href="%s" target="_blank" rel="noreferrer noopener">%s</a>' % (item.group(0), item.group(0))
idx = item.end()
final += text[idx:]
return final