CVE-2015-1226
published 2015-03-09CVE-2015-1226: The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict…
PriorityP427medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.24%
66.3th percentile
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 40.0.2214.115 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vh5c-wx9j-3q9g: The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api
ghsa_unreviewed·2022-05-17
CVE-2015-1226 [MEDIUM] GHSA-vh5c-wx9j-3q9g: The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.
OSV
CVE-2015-1226: The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api
osv·2015-03-09·CVSS 5.0
CVE-2015-1226 [MEDIUM] CVE-2015-1226: The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.
Red Hat
chromium-browser: Validation issue in debugger
vendor_redhat·2015-03-03·CVSS 5.0
CVE-2015-1226 [MEDIUM] CWE-20 chromium-browser: Validation issue in debugger
chromium-browser: Validation issue in debugger
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3244 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
bugzilla·2015-06-17·CVSS 4.9
CVE-2015-3244 [MEDIUM] CVE-2015-3244 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
CVE-2015-3244 JSF: Information disclosure due to missing access restriction in portlet resource dispatching
It was found that JavaServer Faces PortletBridge-based portlets using GenericPortlet's default resource serving did not restrict access to resources within the web application. An attacker could set the resource ID field of a URL to potentially bypass security constraints and gain access to restricted resources.
Discussion:
Acknowledgements:
Red Hat would like to thank Liferay, Inc. for reporting this issue.
---
This issue has been addressed in the following products:
JBoss Portal 6.2.0
Via RHSA-2015:1226 https://rhn.redhat.com/errata/RHSA-2015-1226.html
Bugzilla
CVE-2015-1226 chromium-browser: Validation issue in debugger
bugzilla·2015-03-04·CVSS 5.0
CVE-2015-1226 [MEDIUM] CVE-2015-1226 chromium-browser: Validation issue in debugger
CVE-2015-1226 chromium-browser: Validation issue in debugger
An unspecified validation issue flaw was found in the debugger component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0627 https://rhn.redhat.com/errata/RHSA-2015-0627.html
http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0627.htmlhttp://www.securityfocus.com/bid/72901https://code.google.com/p/chromium/issues/detail?id=456841https://codereview.chromium.org/910053002https://security.gentoo.org/glsa/201503-12http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0627.htmlhttp://www.securityfocus.com/bid/72901https://code.google.com/p/chromium/issues/detail?id=456841https://codereview.chromium.org/910053002https://security.gentoo.org/glsa/201503-12
2015-03-09
Published