Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

a fatal bug that can kill the comment system(用户恶意修改 UA 评论 可影响正常评论加载) #366

Closed
sqlsec opened this issue Jun 16, 2021 · 2 comments
Labels

Comments

@sqlsec
Copy link

sqlsec commented Jun 16, 2021

如果您想报告错误,请提供以下信息 If you want to report a bug, please provide the following information:

可复现问题的步骤 The steps to reproduce.

The latest version of valine is 1.4.14,Let's first look at the effect of normal page loading comments:

image

When the commented user UA is incomplete,such as:

Mozilla/8.0

image

This will cause the entire comment system of the current page to be damaged and the comments cannot be loaded normally
image

可复现问题的网页地址

https://islu.cn/posts/38530.html

This website uses the latest version of valine, the comment cannot be loaded normally

受影响的Valine版本、操作系统,以及浏览器信息

  • Valine 1.4.14
  • OS:Windows/Linux/macOS
  • Browser: Chrome、Firefox、Safair

总的来说就是 如果有用户恶意修改 UA 评论的话,会直接把那个页面评论打瘫痪掉,我是在排查我的一篇 300 多个评论文章的时候发现的,把 leancloud 从里到外排查了一遍 才发现了这个 BUG,希望作者大大后面可以修复这个尴尬的问题

@sqlsec sqlsec changed the title Found a fatal bug that can kill the comment system a fatal bug that can kill the comment system(用户恶意修改 UA 评论 可影响正常评论加载) Jun 16, 2021
@xCss
Copy link
Owner

xCss commented Oct 21, 2021

@sqlsec 你好,我这边本地测试没法复现这个Bug 😢

@stale
Copy link

stale bot commented Apr 16, 2022

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix label Apr 16, 2022
@sqlsec sqlsec closed this as completed May 31, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants