Описание
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 65.0.3325.181-0ubuntu0.17.10.1 |
| bionic | not-affected | 65.0.3325.146-0ubuntu1 |
| cosmic | not-affected | 65.0.3325.146-0ubuntu1 |
| devel | not-affected | 65.0.3325.146-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [65.0.3325.181-0ubuntu0.14.04.1]] |
| precise/esm | DNE | |
| trusty | released | 65.0.3325.181-0ubuntu0.14.04.1 |
| trusty/esm | DNE | trusty was released [65.0.3325.181-0ubuntu0.14.04.1] |
| upstream | released | 65.0.3325.146 |
| xenial | released | 65.0.3325.181-0ubuntu0.16.04.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | DNE | |
| cosmic | DNE | |
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was ignored [Ubuntu touch end-of-life]] |
| esm-infra/xenial | ignored | Ubuntu touch end-of-life |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | DNE | trusty was ignored [Ubuntu touch end-of-life] |
| upstream | needs-triage |
Показывать по
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior ...
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
4.3 Medium
CVSS2
6.1 Medium
CVSS3