question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Universal XSS in Android WebView

See original GitHub issue

Bug description: Today we got a vulnerability report from npm: https://www.npmjs.com/advisories/1560

I’m only creating this issue to track progress on it, I apologize in advance if this is not the right place or way to do so.

To Reproduce: Run yarn audit

Expected behavior: No vulnerabilities found

Environment:

  • OS: any
  • OS version: any
  • react-native version: 0.62.2
  • react-native-webview version: 10.8.3

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Reactions:21
  • Comments:12 (2 by maintainers)

github_iconTop GitHub Comments

6reactions
win-perlegocommented, Oct 5, 2020

We have also received a warning from Github, see attached screenshot.

Can someone provide estimate for the fix #1663 to be merged in? Thank you so much.

Screenshot 2020-10-05 at 17 07 13

5reactions
amardeepranucommented, Nov 18, 2020

Any updates here?

Read more comments on GitHub >

github_iconTop Results From Across the Web

Universal XSS in Android WebView (CVE-2020-6506)
CVE-2020-6506 (crbug.com/1083819) is a universal cross-site scripting (UXSS) vulnerability in Android WebView which allows cross-origin ...
Read more >
Exploiting Android WebView Vulnerabilities | by Kal | Mobis3c
XSS Alert. We have covered 4 Vulnerabilities related to WebViews. Exported WebView (WebView Hijacking); Universal File access from file is enabled for WebView...
Read more >
How would someone XSS into a WebView?
1 Answer 1 · Successfully deliver a XSS payload · Vulnerable webpage is used by the mobile app · The mobile app programmatically...
Read more >
Evernote: Universal-XSS, theft of all cookies from all sites, and ...
Oversecured found dangerous vulnerabilities in the Evernote app for Android, which could have allowed access to user accounts to be ...
Read more >
Android WebView Universal Cross-site Scripting · CVE-2020 ...
A universal cross-site scripting (UXSS) vulnerability, CVE-2020-6506 (https://crbug.com/1083819), has been identified in the Android WebView ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found