dengliming opened a new issue, #613:
URL: https://github.com/apache/shenyu-dashboard/issues/613

   ## Description
   Plugin-handle definitions (`plugin_handle.ext_obj.rule`) are entered through 
the PluginHandle page and stored on the server. When a selector/rule/plugin 
form is rendered, the dashboard builds the antd validation `pattern` with 
`eval(checkRule)`. Anyone with `system:pluginHandler:edit` permission (or 
anyone who can write to the database) can store an arbitrary JavaScript 
expression that then runs in the browser of every administrator who opens the 
corresponding editor – a stored-XSS equivalent. A non-regex string also throws 
during render and crashes the page.
   
   ## Location
   (Lines refer to `master @ 83969a5`.)
   - `src/routes/Plugin/Common/Selector.js:785,1556`
   - `src/routes/Plugin/Common/CommonRuleHandle.js:105`
   - `src/routes/Plugin/Discovery/ProxySelectorModal.js:394,627`
   - `src/routes/System/Plugin/AddModal.js:176`
   - `src/routes/System/NamespacePlugin/AddModal.js:183`
   
   ## Impact
   Privilege escalation from "can edit plugin handles" to "can run code as any 
admin" (token is kept in `sessionStorage`); also a page crash for any malformed 
rule string.
   
   ## Suggested fix
   Replace `eval(checkRule)` with `new RegExp(checkRule)` wrapped in 
`try/catch` (fall back to no pattern on failure). If rules are stored in 
`/regex/flags` form, parse them explicitly instead of evaluating.
   
   ## Related existing
   None
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to