@samitouri / QOS-React-2 / commits / e5cc1462b3

Fix mistyped script arbitrary code execution vulnerability (#18660)

* add test to trustedTypes-test.internal.js * fix mistyped script arbitrary code execution * Removed redundant .toLowerCase() call Co-authored-by: Brian Vaughn <brian.david.vaughn@gmail.com>

Nick Reiley committed Apr 22, 2020 at 00:10 UTC e5cc1462b3e7be78306a1f6961ce82d942eb36d2
2 files changed +20 -2
packages/react-dom/src/client/ReactDOMComponent.js
+4 -2
@@ -430,11 +430,13 @@ export function createElement(
430 namespaceURI = getIntrinsicNamespace(type);
431 }
432 if (namespaceURI === HTML_NAMESPACE) {
433 + const lowerCaseType = type.toLowerCase();
434 +
435 if (__DEV__) {
436 isCustomComponentTag = isCustomComponent(type, props);
437 // Should this check be gated by parent namespace? Not sure we want to
438 // allow <SVG> or <mATH>.
437 - if (!isCustomComponentTag && type !== type.toLowerCase()) {
439 + if (!isCustomComponentTag && type !== lowerCaseType) {
440 console.error(
441 '<%s /> is using incorrect casing. ' +
442 'Use PascalCase for React components, ' +
@@ -444,7 +446,7 @@ export function createElement(
446 }
447 }
448
447 - if (type === 'script') {
449 + if (lowerCaseType === 'script') {
450 // Create the script via .innerHTML so its "parser-inserted" flag is
451 // set to true and it does not execute
452 const div = ownerDocument.createElement('div');
packages/react-dom/src/client/__tests__/trustedTypes-test.internal.js
+16
@@ -242,4 +242,20 @@ describe('when Trusted Types are available in global object', () => {
242 // check that the warning is printed only once
243 ReactDOM.render(<script>alert("I am not executed")</script>, container);
244 });
245 +
246 + it('should warn twice when rendering scRipt tag and prevent code execution on mistyped tag', () => {
247 + expect(() => {
248 + ReactDOM.render(<scRipt>alert("I am not executed")</scRipt>, container);
249 + }).toErrorDev([
250 + 'Warning: <scRipt /> is using incorrect casing. ' +
251 + 'Use PascalCase for React components, ' +
252 + 'or lowercase for HTML elements.\n' +
253 + ' in scRipt (at **)',
254 + 'Warning: Encountered a script tag while rendering React component. ' +
255 + 'Scripts inside React components are never executed when rendering ' +
256 + 'on the client. Consider using template tag instead ' +
257 + '(https://developer.mozilla.org/en-US/docs/Web/HTML/Element/template).\n' +
258 + ' in scRipt (at **)',
259 + ]);
260 + });
261 });