Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

webcam.swf's allowDomain * detected as potential vulnerability #324

Open
ywarnier opened this issue Mar 9, 2021 · 1 comment
Open

webcam.swf's allowDomain * detected as potential vulnerability #324

ywarnier opened this issue Mar 9, 2021 · 1 comment

Comments

@ywarnier
Copy link

ywarnier commented Mar 9, 2021

A security scan reported that webcam.swf contains a wildcard in the allowDomain method, which is considered insecure.

Impact
Very relaxed cross-domain permissions may enable attacker to perform spoofing and data theft attacks.
Solution
The recommendation is to use more restrictive wildcards to grant cross-domain permissions only to domains and sub domains that are really trusted. For more details on Security.allowDomain plese see the help document by Adobe: http://help.adobe.com/en_US/FlashPlatform/reference/actionscript/3/flash/system/Security.html

I'm not sure whether the right solution is to offer a configuration setting somewhere that the SWF can load, or whether webcam.swf should simply be removed (after all, Flash is unmaintained and thus is not considered safe in general anymore), but I wanted to make sure you are aware of the potential issue.

@jtboing
Copy link

jtboing commented Jul 15, 2021

Any updates on this? I've found the same thing as well when scanning vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants