RoSE Extension

ID: bdimfdbofjdbpjgpadkcoffiolffblal

Could be malicious

Extension Info & Metadata

Status
Removed
Version
0.0.9
Size
0.17 MB
Rating
0.0/5
Reviews
0
Users
113,282
Type
Extension
Updated
Nov 6, 2020
Category
7_productivity
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
service.enterprise.extensionsView Profile
Country
CH
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Address
Grenzacherstrasse 124 Basel 4058 CH
Total Extensions
14
Active
5
Obsolete
9
Listed
13
Unlisted
1
Total Users
116,728

Roche Service Experience Extension

Redirection to the Roche Service Experience portal (RoSE) URL

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 15% increase: Older manifest version lacks modern security controls
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2

'unsafe-eval' in the CSP is a hygiene issue inherited from older jQuery builds; it permits eval() inside the extension popup. With zero permissions this is exploitable only via XSS inside the popup itself, which has no external input surface. Low risk in practice but should be replaced with a stricter CSP in any future version.

manifest.json (Line 7)
{  "content_security_policy": "script-src 'self' 'unsafe-eval'; object-src 'self'"}

By severity

Critical0
High0
Medium0
Low1

Versions scanned

None of the 1 scanned version has more than one unique code-review finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
No versions with multiple unique findings.

Files with findings

1 distinct path — top paths by unique finding count:

  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Other
low
manifest.json (line 7)'unsafe-eval' in the CSP is a hygiene issue inherited from older jQuery builds; it permits eval() inside the extension popup. With zero permissions this is exploitable only via XSS inside the popup itself, which has n…
URLs
6
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

rose.roche.com-https://rose.roche.com
jquery.com-https://jquery.com/
sizzlejs.com-https://sizzlejs.com/
jquery.org/licensehttps://jquery.org/license
jquery.org/licensehttp://jquery.org/license
clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
0.0.9
Latest
0.17 MB
Malicious
1N/A
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.