Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g86g-ggjj-ppxm

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

EPSS

Процентиль: 78%
0.0111
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 11 лет назад

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

redhat
почти 11 лет назад

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

nvd
почти 11 лет назад

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

debian
почти 11 лет назад

The URLRequest::GetHSTSRedirect function in url_request/url_request.cc ...

fstec
почти 11 лет назад

Уязвимость браузера Google Chrome, позволяющая удаленному нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 78%
0.0111
Низкий

Дефекты

CWE-200