[Webkit-unassigned] [Bug 16523] Calling window.open("", "foo") allows arbitrary scripting by any domain

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Thu Dec 20 14:52:30 PST 2007


http://bugs.webkit.org/show_bug.cgi?id=16523


sam at webkit.org changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
              Group|Security-Sensitive          |
             Status|UNCONFIRMED                 |NEW
     Ever Confirmed|0                           |1




------- Comment #4 from sam at webkit.org  2007-12-20 14:52 PDT -------
Adam!  We have been working to make a similar system to mozilla regarding
hiding security sensitive bugs.  This bug is now marked as such and cannot be
seen by anyone outside the cc list and the reporter and the security group
(which for the moment, while we test the system, is just me and Mark Rowe).  We
will be making more formal statement about the security group soon.


-- 
Configure bugmail: http://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list