Project

General

Profile

Actions

Bug #100234

closed

Incorporate tests of enshrined/svg-sanitize:v0.16.0

Added by Oliver Hader about 1 year ago. Updated about 1 year ago.

Status:
Rejected
Priority:
Should have
Assignee:
Category:
Security
Target version:
-
Start date:
2023-03-21
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
12
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

It looks like the security release enshrined/svg-sanitize:v0.16.0 did not fix a real vulnerability and was a false-positive:

Passing the two new added test files with the previous version v0.15.4 of that package did not reveal any valid attack vector - all entities are correctly encoded and would not have lead to an exploit in a browser context. This change in the TYPO3 context aims to demonstrate that there is no vulnerability.


Related issues 2 (1 open1 closed)

Related to TYPO3 Core - Task #100233: Upgrade enshrined/svg-sanitize to ^0.16Rejected2023-03-20

Actions
Related to TYPO3 Core - Task #103722: Detected vulnerability with package 'enshrined/svg-sanitize' New2024-04-25

Actions
Actions #1

Updated by Oliver Hader about 1 year ago

  • Related to Task #100233: Upgrade enshrined/svg-sanitize to ^0.16 added
Actions #2

Updated by Gerrit Code Review about 1 year ago

  • Status changed from New to Under Review

Patch set 1 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/78193

Actions #3

Updated by Gerrit Code Review about 1 year ago

Patch set 2 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/78193

Actions #4

Updated by Oliver Hader about 1 year ago

  • Status changed from Under Review to Rejected

CVE was rejected

Actions #5

Updated by Lars Tode 2 days ago

  • Related to Task #103722: Detected vulnerability with package 'enshrined/svg-sanitize' added
Actions

Also available in: Atom PDF