Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5236

Опубликовано: 11 нояб. 2021
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

It was discovered that the IcedTea-Web used codebase attribute of the tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

A flaw was discovered that IcedTea-Web did not properly determine an applet's origin when performing same-origin checks. A malicious page could use this flaw to bypass the Same Origin Policy (SOP) and access data on unrelated sites using a spoofed value for the applet's codebase attribute.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6icedtea-webWill not fix
Red Hat Enterprise Linux 7icedtea-webWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1256403icedtea-web: SOP checks based on codebase and not applet origin

EPSS

Процентиль: 53%
0.00786
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

CVSS3: 7.5
nvd
около 4 лет назад

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

CVSS3: 7.5
debian
около 4 лет назад

It was discovered that the IcedTea-Web used codebase attribute of the ...

CVSS3: 7.5
github
около 4 лет назад

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

EPSS

Процентиль: 53%
0.00786
Низкий

5.8 Medium

CVSS2

Уязвимость CVE-2015-5236