Описание
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 59.0.3071.109-0ubuntu1.1360 |
| bionic | released | 59.0.3071.109-0ubuntu1.1360 |
| cosmic | released | 59.0.3071.109-0ubuntu1.1360 |
| devel | released | 59.0.3071.109-0ubuntu1.1360 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [59.0.3071.109-0ubuntu0.14.04.1186]] |
| precise/esm | DNE | |
| trusty | released | 59.0.3071.109-0ubuntu0.14.04.1186 |
| trusty/esm | DNE | trusty was released [59.0.3071.109-0ubuntu0.14.04.1186] |
| upstream | released | 59.0.3071.86 |
| vivid/stable-phone-overlay | DNE |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [Ubuntu touch end-of-life]] |
| esm-infra/xenial | ignored | Ubuntu touch end-of-life |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | trusty was ignored [Ubuntu touch end-of-life] |
| upstream | needs-triage |
Показывать по
EPSS
4.3 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
Inappropriate implementation in CSP reporting in Blink in Google Chrom ...
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
Уязвимость модуля отображения Blink браузера Google Chrome, позволяющая нарушителю получить значения фрагментов URL
EPSS
4.3 Medium
CVSS2
4.3 Medium
CVSS3