Settings

Theme

Security vulnerability in Chrome's JSONView extension?

6 points by Pyppe 9 years ago · 4 comments · 1 min read


I've used daily the JSONView Chrome extension (previously available in https://chrome.google.com/webstore/detail/jsonview/chklaanhfefbnpoihckbnefhakgolnmc?hl=en) for viewing JSON.

Just now I noticed that it has been automatically disabled from my browser. Visiting `chrome://extensions/` states "This extension contains a serious security vulnerability". And also, it's no longer available in the Chrome Web Store (see link above).

Any idea, what's the vulnerability? I tried to google, but found no info about this...

PyppeOP 9 years ago

https://github.com/gildas-lormeau/JSONView-for-Chrome/pull/4... maybe it's about this XSS issue. Funny though, that the extension it's just now suddenly being pulled out.

I would've imagined this extension being used by A LOT of developers...

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection