{"id":"GHSA-qm5v-pj64-852j","aliases":[],"url":"https://o3.security/vulnerability/GHSA-qm5v-pj64-852j","summary":"Passbolt Api Tabnabbing when opening URI with menu \"Open URI in a new tab\"","details":"### Description\nA user could create and share a resource with a malicious URI. When the victim opens with menu “Open URI in a new tab” function, the malicious page has access to the window.opener object.\n\n### Impact of issue\nThe newly opened malicious page can for example change the window.opener.location to redirect the user to a phishing page, or call a JavaScript function served by the AppJS on the user behalf for example to try to affect the integrity of the data.\n\n### Fix\nThe code that opens a new window via window.open(); now open the tab with the noopener attribute.","published":"2024-05-20T17:09:57Z","modified":"2024-12-05T05:36:29.026187Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"passbolt/passbolt_api","fixedVersion":"2.11.0"}],"fix":{"url":"https://github.com/passbolt/passbolt_api/commit/f568e113beb3134446eda9e66400d28d726ee20d","label":"passbolt/passbolt_api@f568e11"},"references":[{"type":"WEB","url":"https://github.com/passbolt/passbolt_api/commit/f568e113beb3134446eda9e66400d28d726ee20d"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/passbolt/passbolt_api/2019-08-07-3.yaml"},{"type":"PACKAGE","url":"https://github.com/passbolt/passbolt_api"},{"type":"WEB","url":"https://www.passbolt.com/incidents/20190807_multiple_vulnerabilities"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:36:29.026187Z"}}