Описание
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity: Medium)
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 108.0.5359.71-0ubuntu0.18.04.5 |
| devel | not-affected | code not present |
| esm-infra/focal | DNE | focal was not-affected [code not present] |
| focal | not-affected | code not present |
| jammy | not-affected | code not present |
| kinetic | not-affected | code not present |
| trusty | ignored | end of standard support |
| upstream | released | |
| xenial | ignored | end of standard support |
Показывать по
4.3 Medium
CVSS3
Связанные уязвимости
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2022-4186 Insufficient validation of untrusted input in Downloads
Insufficient validation of untrusted input in Downloads in Google Chro ...
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass Downloads restrictions via a crafted HTML page. (Chromium security severity: Medium)
Уязвимость компонента Downloads браузеров Microsoft Edge и Google Chrome, позволяющая нарушителю оказать воздействие на целостность данных
4.3 Medium
CVSS3