Executive brief
Twitter-Post-Fetcher is a JavaScript library that displays tweets on web pages. The library opens links in new browser tabs without protection, allowing those external pages to access and potentially manipulate the parent page through the browser's window.opener property. This could enable an attacker to deface the hosting website or redirect users to malicious sites.
Technical details
Twitter-Post-Fetcher contains a use-of-untrusted-web-link vulnerability (CWE-1022) in its link-target handler (js/twitterFetcher.js). When opening external links in new tabs via target="_blank", the library fails to include the rel="noopener" attribute, allowing the opened page to retain access to the parent page via window.opener. This permits the target page to modify or navigate the parent window. The vulnerability affects versions up to 17.x and requires user interaction (clicking a link). A fix was released in version 18.0.0 via commit 7d281c6fb5acbc29a2cad295262c1f0c19ca56f3.
Affected products
- Jason Mayes Twitter-Post-Fetcher up to 17.x
Timeline
- 2022-12-29: disclosed: Advisory published
- 2023: patched: Fixed in version 18.0.0