In D8, we used HTML5 localStorage everywhere. One of example is Toolbar module. It saved the reusable toolbar HTML code for next calls.
Attackers able to inject malicious data into localStorage for next login users (who will use the same devices.)
You can see this by:
====================
** WITH SAME DEVICES ONLY **
A:
1. [ATTACKERS]: Open Console and inject:
localStorage.setItem('Drupal.toolbar.subtrees.bartik', '{"system-admin_content":"
alert(1)","help-main":""}');
localStorage.setItem('Drupal.toolbar.trayVerticalLocked', true)
2. [USER]: Login
3. [USER B]: Login
B:
1. User A login, switch to Vertical Toolbar.
2. User A logout.
3. [ATTACKERS]: Open Console and localStorage.getItem
Proposed resolution:
============
Toolbar Module:
- To encode hash with user token in _toolbar_get_subtrees_hash.
CORE:
- Clean up localStorage (also sessionStorage) during login & logout
- Switch all localStorage for HTML to sessionStorage
Note: sessionStorage is not shared with Tabs
Reported by droplet
Comments
Comment #2
shrop commentedSome thoughts and questions for clarification/planning:
Comment #10
nod_Filled against the toolbar but it's a general issue about the data left in the browser cache.
Comment #17
prudloff commentedWe could use the Clear-Site-Data header on logout responses.
I think I remember seeing an issue about this header but I can't find it.
Comment #19
quietone commentedThe Toolbar Module was approved for removal in #3476882: [Policy] Move Toolbar module to contrib.
This is Postponed. The status is set according to two policies. The Remove a core extension and move it to a contributed project and the Extensions approved for removal policies.
The deprecation work is in #3484850: [meta] Tasks to deprecate Toolbar module and the removal work in #3488828: [meta] Tasks to remove Toolbar module.
Toolbar will be moved to a contributed project before Drupal 12.0.0 is released.
Comment #20
quietone commentedToolbar has moved to contrib