Unpreventable top-level navigation
Package
Affected versions
>= 8.0.0-beta.0, < 8.5.1
>= 9.0.0-beta.0, < 9.3.0
>= 10.0.0-beta.0, < 10.0.1
Patched versions
8.5.1
9.3.0
10.0.1
Description
Reviewed
Oct 6, 2020
Published to the GitHub Advisory Database
Oct 6, 2020
Published by the National Vulnerability Database
Oct 6, 2020
Last updated
Feb 1, 2023
Impact
The
will-navigate
event that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navigation across sites.Patches
11.0.0-beta.1
10.0.1
9.3.0
8.5.1
Workarounds
Sandbox all your iframes using the
sandbox
attribute. This will prevent them creating top-frame navigations and is good practice anyway.For more information
If you have any questions or comments about this advisory:
References