Fix mistyped script arbitrary code execution vulnerability (#18660)
* add test to trustedTypes-test.internal.js * fix mistyped script arbitrary code execution * Removed redundant .toLowerCase() call Co-authored-by: Brian Vaughn <brian.david.vaughn@gmail.com>
Nick Reiley committed
Apr 22, 2020 at 00:10 UTC
e5cc1462b3e7be78306a1f6961ce82d942eb36d2
2 files changed
+20
-2
packages/react-dom/src/client/ReactDOMComponent.js
+4
-2
@@ -430,11 +430,13 @@ export function createElement(
430
namespaceURI = getIntrinsicNamespace(type);
431
}
432
if (namespaceURI === HTML_NAMESPACE) {
433
+ const lowerCaseType = type.toLowerCase();
434
+
435
if (__DEV__) {
436
isCustomComponentTag = isCustomComponent(type, props);
437
// Should this check be gated by parent namespace? Not sure we want to
438
// allow <SVG> or <mATH>.
437
- if (!isCustomComponentTag && type !== type.toLowerCase()) {
439
+ if (!isCustomComponentTag && type !== lowerCaseType) {
440
console.error(
441
'<%s /> is using incorrect casing. ' +
442
'Use PascalCase for React components, ' +
@@ -444,7 +446,7 @@ export function createElement(
446
}
447
}
448
447
- if (type === 'script') {
449
+ if (lowerCaseType === 'script') {
450
// Create the script via .innerHTML so its "parser-inserted" flag is
451
// set to true and it does not execute
452
const div = ownerDocument.createElement('div');
packages/react-dom/src/client/__tests__/trustedTypes-test.internal.js
+16
@@ -242,4 +242,20 @@ describe('when Trusted Types are available in global object', () => {
242
// check that the warning is printed only once
243
ReactDOM.render(<script>alert("I am not executed")</script>, container);
244
});
245
+
246
+ it('should warn twice when rendering scRipt tag and prevent code execution on mistyped tag', () => {
247
+ expect(() => {
248
+ ReactDOM.render(<scRipt>alert("I am not executed")</scRipt>, container);
249
+ }).toErrorDev([
250
+ 'Warning: <scRipt /> is using incorrect casing. ' +
251
+ 'Use PascalCase for React components, ' +
252
+ 'or lowercase for HTML elements.\n' +
253
+ ' in scRipt (at **)',
254
+ 'Warning: Encountered a script tag while rendering React component. ' +
255
+ 'Scripts inside React components are never executed when rendering ' +
256
+ 'on the client. Consider using template tag instead ' +
257
+ '(https://developer.mozilla.org/en-US/docs/Web/HTML/Element/template).\n' +
258
+ ' in scRipt (at **)',
259
+ ]);
260
+ });
261
});