dengliming opened a new issue, #614:
URL: https://github.com/apache/shenyu-dashboard/issues/614

   ## Description
   When the debug response is not JSON, `ApiDebug` renders 
`ReactHtmlParser(responseInfo.body)` directly into the dashboard DOM. The body 
comes from whatever upstream the gateway proxies to (or any address the user is 
pointed at via the environment selector), so `<iframe>`, `<form>`, `<style>`, 
`<a href="javascript:...">` etc. in the response are rendered inside the 
authenticated admin origin.
   
   ## Location
   (Lines refer to `master @ 83969a5`.)
   - `src/routes/Document/components/ApiDebug.js:40,493`
   
   ## Impact
   A malicious or compromised upstream can inject markup into the admin page 
(phishing forms, clickjacking, style injection). Script tags are stripped by 
react-html-parser, but the remaining vectors are still significant for an admin 
UI whose token is in `sessionStorage`.
   
   ## Suggested fix
   Render non-JSON bodies as plain text inside a `<pre>` (or in a read-only 
textarea) and drop the `react-html-parser` dependency from this component.
   
   ## Related existing
   None
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to