3 ms·
Possible supply-chain "attack" (or demonstration, from what I can tell) on wherever they get their polyfill library? It's coming from: https://polyfill.archive
by stebalien 2y ago
Possible supply-chain "attack" (or demonstration, from what I can tell) on wherever they get their polyfill library? It's coming from:
https://polyfill.archive.org/v3/polyfill.min.js?features=fetch%2CIntersectionObserver%2CResizeObserver%2CglobalThis%2CElement.prototype.getAttributeNames%2CString.prototype.startsWith%2CArray.prototype.flat%2CURL%2CURLSearchParams https://polyfill.archive.org/v3/polyfill.min.js?features=fet...
- TZubiri 2y agoPossibly unrelated. How can they elevate from a script injected in the frontend to the database of all users? Also, the vulnerability seems to be a domain overtake. But Archive is self hosting a static version of the dependency?
- jszymborski 2y agoOne way would might be to capture credentials for admin accounts if they have a "god mode".