Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqw3-7f5v-7r6j

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

EPSS

Процентиль: 21%
0.00069
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 6 лет назад

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS3: 4.3
redhat
больше 6 лет назад

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS3: 4.3
nvd
около 6 лет назад

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS3: 4.3
debian
около 6 лет назад

Insufficient data validation in CORS in Google Chrome prior to 76.0.38 ...

CVSS3: 4.3
fstec
больше 6 лет назад

Уязвимость веб-браузера Google Chrome, связанная с некорректной фильтрацией портов в CORS, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 21%
0.00069
Низкий

Дефекты

CWE-20