Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36j3-xxf7-4pqg

Опубликовано: 02 окт. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Android WebView Universal Cross-site Scripting

A universal cross-site scripting (UXSS) vulnerability, CVE-2020-6506 (https://crbug.com/1083819), has been identified in the Android WebView system component, which allows cross-origin iframes to execute arbitrary JavaScript in the top-level document. This vulnerability affects React Native apps which use a react-native-webview that allows navigation to arbitrary URLs, and when that app runs on systems with an Android WebView version prior to 83.0.4103.106.

Pending mitigation

Ensure users update their Android WebView system component via the Google Play Store to 83.0.4103.106 or higher to avoid this UXSS. 'react-native-webview' is working on a mitigation but it could take some time.

References

https://alesandroortiz.com/articles/uxss-android-webview-cve-2020-6506/

Ссылки

Пакеты

Наименование

react-native-webview

npm
Затронутые версииВерсия исправления

<= 10.10.2

11.0.0

EPSS

Процентиль: 80%
0.01414
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79
CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVSS3: 8.8
redhat
больше 5 лет назад

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVSS3: 6.5
nvd
больше 5 лет назад

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVSS3: 6.5
debian
больше 5 лет назад

Insufficient policy enforcement in WebView in Google Chrome on Android ...

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость компонента WebView браузера Google Chrome, позволяющая нарушителю обойти существующие ограничения безопасности с помощью специально созданной HTML страницы

EPSS

Процентиль: 80%
0.01414
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79
CWE-863