Project

General

Profile

Actions

Bug #98492

closed

Mitigate Browser "Spell-Jacking"

Added by Oliver Hader about 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Security
Target version:
-
Start date:
2022-10-01
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
10
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

The following issue has been brought to the attention of the security team.
Source: https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords

Having manually(!) enabled "enhanced spell checking" in browsers, can lead to scenarios that password data is sent to remote services that actually take care of the spell checking. Since this issue is cause by browsers and the determination of "confidentiality" is fuzzy here, this issue is handled in public. For instance, any content that is only available in an intranet would be considered confidential, it's not only about password data.

The suggestion for the TYPO3 core is:


Related issues 1 (0 open1 closed)

Related to TYPO3 Core - Bug #98504: Mitigate Browser "Spell-Jacking" in Setup ModuleClosedOliver Hader2022-10-03

Actions
Actions #1

Updated by Oliver Hader about 2 years ago

  • Category set to Security
Actions #2

Updated by Oliver Hader about 2 years ago

  • Description updated (diff)
Actions #3

Updated by Oliver Hader about 2 years ago

  • Description updated (diff)
Actions #4

Updated by Gerrit Code Review about 2 years ago

  • Status changed from New to Under Review

Patch set 1 for branch main of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/75930

Actions #5

Updated by Oliver Hader about 2 years ago

  • Status changed from Under Review to Resolved
  • % Done changed from 0 to 100
Actions #6

Updated by Oliver Hader about 2 years ago

  • Related to Bug #98504: Mitigate Browser "Spell-Jacking" in Setup Module added
Actions #7

Updated by Gerrit Code Review about 2 years ago

  • Status changed from Resolved to Under Review

Patch set 1 for branch 11.5 of project Packages/TYPO3.CMS has been pushed to the review server.
It is available at https://review.typo3.org/c/Packages/TYPO3.CMS/+/75946

Actions #8

Updated by Oliver Hader about 2 years ago

  • Status changed from Under Review to Resolved
Actions #9

Updated by Benni Mack almost 2 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF