Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5118

Опубликовано: 05 сент. 2017
Источник: redhat
CVSS3: 6.5

Описание

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1488779chromium-browser: bypass of content security policy in blink

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 8 лет назад

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVSS3: 4.3
nvd
больше 8 лет назад

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVSS3: 4.3
debian
больше 8 лет назад

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Lin ...

CVSS3: 4.3
github
больше 3 лет назад

Blink in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, failed to correctly propagate CSP restrictions to javascript scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

6.5 Medium

CVSS3