RainLoop / rainloop-webmail

Simple, modern & fast web-based email client
http://rainloop.net
MIT License
4.1k stars 890 forks source link

Sec: Fix CVE-2022-29360 XSS vulnerability #2183

Closed sadsfae closed 2 years ago

sadsfae commented 2 years ago

(patch credit)

Neustradamus commented 2 years ago

@RainLoop: Can you look?

nerzhul commented 2 years ago

project seems dead author or company just resigned :(

Neustradamus commented 2 years ago

Please use SnappyMail from @the-djmaze, we can thanks for this work!

Please note that SnappyMail supports SCRAM-SHA-* for connection, very good security:

Linked to:

RainLoop commented 2 years ago

Fixed

Neustradamus commented 2 years ago

@RainLoop: Where is the fix?

RainLoop commented 2 years ago

https://github.com/RainLoop/rainloop-webmail/pull/2187 https://github.com/RainLoop/rainloop-webmail/pull/2187/files#diff-22b1d644ea4075b18f15da66d7f277924b8df180700f379cb6eef964a9736c07R242

sadsfae commented 2 years ago

Welcome back @RainLoop

ShamimIslam commented 1 year ago

This issue is fixed. Let's back off from the hype. The replacement body item is now random hash. Thanks. v0.17 does not have this.