Junglewise Threat Intelligence

CVE-2020-11611: xdLocalStorage open redirect via unsafe postMessage targetOrigin

CVE-2020-11611 · Severity: low · CVSS 3.1 · Published 2021-12-09

Technologies: Ofirdagan Xdlocalstorage. Vendors: npm.

Executive brief

xdLocalStorage is a JavaScript library that enables web applications to share data across different domains using cross-origin communication. The library's buildMessage() function uses a wildcard (*) as the targetOrigin when sending messages via postMessage(), allowing any domain loaded in an iframe to intercept sensitive messages intended for cross-domain storage operations. This misconfiguration could enable attackers to redirect users or intercept stored data.

Technical details

The vulnerability is an open redirect / insecure postMessage implementation (CWE-601) in the xdLocalStorage library through version 2.0.5. The root cause is that the buildMessage() function specifies a wildcard (*) as the targetOrigin parameter in postMessage() calls to iframe objects, rather than restricting messages to a specific trusted origin. This allows any domain currently loaded within the iframe to receive and potentially act upon messages from the client. An attacker with control over a domain loaded in a framed context could intercept these messages or trigger unintended navigation. No special authentication or unusual user interaction is required beyond normal library usage, though the attacker must control the iframe's loaded domain. The fix is to replace the wildcard with an explicit, trusted targetOrigin value.

Affected products

  • ofirdagan xdLocalStorage through 2.0.5

Timeline

  • 2021-12-09: disclosed
  • 2020-04-07: advisory: NVD publication date

References

Related threats