Universal XSS in Android WebView
See original GitHub issueBug description: Today we got a vulnerability report from npm: https://www.npmjs.com/advisories/1560
I’m only creating this issue to track progress on it, I apologize in advance if this is not the right place or way to do so.
To Reproduce:
Run yarn audit
Expected behavior: No vulnerabilities found
Environment:
- OS: any
- OS version: any
- react-native version: 0.62.2
- react-native-webview version: 10.8.3
Issue Analytics
- State:
- Created 3 years ago
- Reactions:21
- Comments:12 (2 by maintainers)
Top Results From Across the Web
Universal XSS in Android WebView (CVE-2020-6506)
CVE-2020-6506 (crbug.com/1083819) is a universal cross-site scripting (UXSS) vulnerability in Android WebView which allows cross-origin ...
Read more >Exploiting Android WebView Vulnerabilities | by Kal | Mobis3c
XSS Alert. We have covered 4 Vulnerabilities related to WebViews. Exported WebView (WebView Hijacking); Universal File access from file is enabled for WebView...
Read more >How would someone XSS into a WebView?
1 Answer 1 · Successfully deliver a XSS payload · Vulnerable webpage is used by the mobile app · The mobile app programmatically...
Read more >Evernote: Universal-XSS, theft of all cookies from all sites, and ...
Oversecured found dangerous vulnerabilities in the Evernote app for Android, which could have allowed access to user accounts to be ...
Read more >Android WebView Universal Cross-site Scripting · CVE-2020 ...
A universal cross-site scripting (UXSS) vulnerability, CVE-2020-6506 (https://crbug.com/1083819), has been identified in the Android WebView ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
We have also received a warning from Github, see attached screenshot.
Can someone provide estimate for the fix #1663 to be merged in? Thank you so much.
Any updates here?