Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j594-4mw2-8pmc

Опубликовано: 05 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

A CWE-693 “Protection Mechanism Failure” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

A CWE-693 “Protection Mechanism Failure” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

EPSS

Процентиль: 29%
0.00107
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-184
CWE-693

Связанные уязвимости

CVSS3: 6.8
nvd
почти 2 года назад

A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows a physical attacker to read arbitrary files on the file system, alter the configuration of the embedded browser, and have other unspecified impacts to the confidentiality, integrity, and availability of the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

EPSS

Процентиль: 29%
0.00107
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-184
CWE-693