From 6317ef75a11b471bbb70d080936fcffc0c526caf Mon Sep 17 00:00:00 2001 From: Cheng Zhao Date: Thu, 16 Jul 2020 12:48:01 +0900 Subject: [PATCH] chore: cherry-pick fix from chromium issue 1074317 (#24559) --- patches/chromium/.patches | 1 + patches/chromium/backport_1074317.patch | 89 +++++++++++++++++++++++++ 2 files changed, 90 insertions(+) create mode 100644 patches/chromium/backport_1074317.patch diff --git a/patches/chromium/.patches b/patches/chromium/.patches index cebb3a6840bbe..e71c1aaca1d4b 100644 --- a/patches/chromium/.patches +++ b/patches/chromium/.patches @@ -115,3 +115,4 @@ backport_1063177.patch backport_1019161.patch avoid_using_x11_shm_for_remote_connections.patch backport_1065122.patch +backport_1074317.patch diff --git a/patches/chromium/backport_1074317.patch b/patches/chromium/backport_1074317.patch new file mode 100644 index 0000000000000..b7c4d457a10a2 --- /dev/null +++ b/patches/chromium/backport_1074317.patch @@ -0,0 +1,89 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Cheng Zhao +Date: Thu, 4 Oct 2018 14:57:02 -0700 +Subject: fix: stop leaking cross-origin post-redirect data using StackTrace + +[1074317] [High] [CVE-2020-6511]: Security: The CSP reports and stacktraces of errors leaks post-redirect URL for