Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2816

Опубликовано: 13 нояб. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

РелизСтатусПримечание
dapper

not-affected

no webkit
devel

not-affected

4:4.7.0-0ubuntu2
hardy

not-affected

no webkit
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

4:4.6.2-0ubuntu5.1
maverick

not-affected

4:4.7.0-0ubuntu2
natty

not-affected

4:4.7.0-0ubuntu2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.2.4-1ubuntu1
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

ignored

end of life
karmic

not-affected

1.1.15.2-1
lucid

not-affected

1.2.0-1
maverick

not-affected

1.2.4-1ubuntu1
natty

not-affected

1.2.4-1ubuntu1
upstream

needs-triage

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

redhat
около 16 лет назад

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

nvd
около 16 лет назад

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

debian
около 16 лет назад

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, ...

github
больше 3 лет назад

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

6.8 Medium

CVSS2