Basebelisi ba NoScript ba bile le mathata ka libatli tse ipapisitseng le enjine ea Chromium.

Keketso ea sebatli sa NoScript 11.2.18 e lokollotsoe, e etselitsoe ho thibela khoutu ea JavaScript e kotsi le e sa batleheng, hammoho le mefuta e fapaneng ea litlhaselo (XSS, DNS Rebinding, CSRF, Clickjacking). Beshene e ncha e lokisa bothata bo bakiloeng ke phetoho tseleng ea ho sebetsa file:// URLs moenjineng oa Chromium. Bothata bo ile ba etsa hore ho se khonehe ho bula libaka tse ngata (Gmail, Facebook, joalo-joalo) ka mor'a ho ntlafatsa kenyelletso ho phetolelo ea 11.2.16 ho li-browser tse ncha tse sebelisang mochine oa Chromium (Chrome, Brave, Vivaldi).

Bothata bo bakiloe ke taba ea hore liphetolelong tse ncha tsa Chromium, phihlello ea li-add-on ho "file:///" URL e ne e thibetsoe ka mokhoa o ikhethileng. Bothata ha boa ka ba hlokomeloa hobane bo hlahile feela ha u kenya NoScript ho tsoa lethathamong la li-add-on Store la Chrome. Ha o kenya archive ea zip ho tloha GitHub ka "Moroalo o sa koaloang" menu (chrome://extensions> Developer mode), bothata ha bo hlahe, kaha phihlello ea faele: /// URL ha e thijoe ka mokhoa oa nts'etsopele. Tharollo bakeng sa bothata ke ho nolofalletsa "Lumella ho fihlella li-URL tsa faele" litlhophisong tsa tlatsetso.

Boemo bo ile ba mpefatsoa ke taba ea hore ka mor'a ho beha NoScript 11.2.16 bukeng ea Chrome Web Store, mongoli o ile a leka ho hlakola tokollo, e leng se ileng sa lebisa ho nyamela ha leqephe lohle la morero. Kahoo, ka nako e itseng basebelisi ba ne ba sa khone ho khutlela mofuteng o fetileng mme ba qobelloa ho tima tlatsetso. Leqephe la Lebenkele la Webo la Chrome le se le tsosolositsoe mme bothata bo lokisitsoe tokollong ea 11.2.18. Lenaneng la Lebenkele la Webo la Chrome, molemong oa ho qoba tieho ea ho lekola khoutu ea mofuta o mocha, ho ile ha etsoa qeto ea ho khutlela boemong bo fetileng le ho beha tokollo 11.2.17, e ts'oanang le mofuta o seng o lekoa oa 11.2.11.

Source: opennet.ru

Eketsa ka tlhaloso