Описание
Inappropriate implementation in DevTools in Google Chrome prior to 93.0.4577.63 allowed a remote attacker who had convinced the user to use Chrome headless with remote debugging to execute arbitrary code via a crafted HTML page.
Inappropriate implementation in DevTools in Google Chrome prior to 93.0.4577.63 allowed a remote attacker who had convinced the user to use Chrome headless with remote debugging to execute arbitrary code via a crafted HTML page.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-30618
- https://chromereleases.googleblog.com/2021/08/stable-channel-update-for-desktop_31.html
- https://crbug.com/1232279
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LVY4WIWTVVYKQMROJJS365TZBKEARCF
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPJPUSAWIJMQFBQQQYXAICLI4EKFQOH6
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QW4R2K5HVJ4R6XDZYOJCCFPIN2XHNS3L
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-30618
EPSS
CVE ID
Связанные уязвимости
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Уязвимость набора инструментов DevTools браузера Google Chrome, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании
EPSS