[CVE] Remote code execution due to CSRF on the qute://settings page

Bug #1782456 reported by Simon Quigley
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
qutebrowser (Ubuntu)
Fix Released
Medium
Unassigned
Bionic
In Progress
Medium
Simon Quigley

Bug Description

https://github.com/qutebrowser/qutebrowser/issues/4060

Due to a CSRF vulnerability affecting the qute://settings page, it was
possible for websites to modify qutebrowser settings. Via settings like
editor.command, this possibly allowed websites to execute arbitrary code.

This issue has been assigned CVE-2018-10895.

Simon Quigley (tsimonq2)
Changed in qutebrowser (Ubuntu Bionic):
importance: Undecided → Medium
assignee: nobody → Simon Quigley (tsimonq2)
Changed in qutebrowser (Ubuntu):
status: New → Fix Released
Changed in qutebrowser (Ubuntu Bionic):
status: New → In Progress
Changed in qutebrowser (Ubuntu):
importance: Undecided → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.