-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Mitigate DNS rebinding flaw #5460
Comments
Test Plan
|
hackerone issue: https://hackerone.com/reports/663729 |
Verification PASSED on
Verification passed on
Verification passed on
|
Talked to @GeetaSarvadnya through DM about testing on Windows, note here for future references. |
Mitigate the WebTorrent DNS rebinding flaw disclosed in HackerOne. Low security/privacy risk.
Original issue: brave/browser-laptop#12616
Original Brave PR: brave/browser-laptop#13844
Original WebTorrent PR: webtorrent/webtorrent#1260
Fixed WebTorrent PR: webtorrent/webtorrent#1678
The fix is already published in
webtorrent@0.105.2
. We should update to this version.The text was updated successfully, but these errors were encountered: