Skip to content

Firefox plugin for floccus synchronization was detected as an XXE attack by the WAF #2063

@tin607

Description

@tin607

Which version of floccus are you using?

5.7.0

How many bookmarks do you have, roughly?

30

Are you using other means to sync bookmarks in parallel to floccus?

Yes, I also sync via Google account

Sync method

WebDAV

Which browser are you using? In case you are using the phone App, specify the Android or iOS version and device please.

No response

Which version of Nextcloud Bookmarks are you using? (if relevant)

No response

Which version of Nextcloud? (if relevant)

No response

What kind of WebDAV server are you using? (if relevant)

No response

Describe the Bug

The use of the Firefox plugin for floccus synchronization was detected as an XXE attack by the (safeline)WAF and was intercepted.

Image Image

Expected Behavior

Does flocculus involve dangerous operations? I hope it can be improved.

To Reproduce

no

Debug log provided

  • I have provided a debug log file

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions