Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1617

Опубликовано: 25 янв. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 4.3

Описание

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

РелизСтатусПримечание
devel

released

48.0.2564.82-0ubuntu1.1222
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [48.0.2564.82-0ubuntu0.14.04.1.1108]]
precise

ignored

trusty

released

48.0.2564.82-0ubuntu0.14.04.1.1108
trusty/esm

DNE

trusty was released [48.0.2564.82-0ubuntu0.14.04.1.1108]
upstream

released

48.0.2564.82
vivid

released

48.0.2564.82-0ubuntu0.15.04.1.1193
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

released

48.0.2564.82-0ubuntu0.15.10.1.1219

Показывать по

РелизСтатусПримечание
devel

released

1.12.5-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.12.5-0ubuntu0.14.04.1]]
precise

DNE

trusty

released

1.12.5-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1.12.5-0ubuntu0.14.04.1]
upstream

released

1.12.5
vivid

released

1.12.5-0ubuntu0.15.04.1
vivid/stable-phone-overlay

released

1.12.5-0ubuntu0.15.04.1~overlay1
vivid/ubuntu-core

DNE

wily

released

1.12.5-0ubuntu0.15.10.1

Показывать по

EPSS

Процентиль: 70%
0.00635
Низкий

4.3 Medium

CVSS2

4.3 Medium

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
nvd
около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

CVSS3: 4.3
debian
около 10 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/ ...

CVSS3: 4.3
github
больше 3 лет назад

The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report.

fstec
около 10 лет назад

Уязвимость браузера Google Chrome, позволяющая нарушителю определить, какой веб-сайт был посещен с использованием HSTS-соединения

EPSS

Процентиль: 70%
0.00635
Низкий

4.3 Medium

CVSS2

4.3 Medium

CVSS3