CVE-2016-2845
published 2016-03-06CVE-2016-2845: The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of…
PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.22%
81.0th percentile
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 48.0.2564.116 | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-03-10·CVSS 8.8
CVE-2016-1630 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
It was discovered that the ContainerNode::parserRemoveChild function in
Blink mishandled widget updates in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1630)
It was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun
function in Chromium mishandled nested message loops. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1631)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacker could potentia
Red Hat
chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
vendor_redhat·2015-11-22·CVSS 5.3
CVE-2016-2845 [MEDIUM] chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
GHSA
GHSA-gpvp-v7vw-rjmm: The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49
ghsa_unreviewed·2022-05-17
CVE-2016-2845 [MEDIUM] CWE-200 GHSA-gpvp-v7vw-rjmm: The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
OSV
oxide-qt vulnerabilities
osv·2016-03-10·CVSS 8.8
CVE-2016-1630 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
It was discovered that the ContainerNode::parserRemoveChild function in
Blink mishandled widget updates in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1630)
It was discovered that the PPB_Flash_MessageLoop_Impl::InternalRun
function in Chromium mishandled nested message loops. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1631)
Multiple use-after-frees were discovered in Blink. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit these to cause a denial of service via renderer
OSV
CVE-2016-2845: The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49
osv·2016-03-05·CVSS 5.3
CVE-2016-2845 [MEDIUM] CVE-2016-2845: The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://homakov.blogspot.com/2014/01/using-content-security-policy-for-evil.htmlhttp://www.securityfocus.com/bid/84168http://www.securitytracker.com/id/1035185http://www.ubuntu.com/usn/USN-2920-1https://bugs.chromium.org/p/chromium/issues/detail?id=542060https://code.google.com/p/chromium/issues/detail?id=591402https://codereview.chromium.org/1454003003/http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://homakov.blogspot.com/2014/01/using-content-security-policy-for-evil.htmlhttp://www.securityfocus.com/bid/84168http://www.securitytracker.com/id/1035185http://www.ubuntu.com/usn/USN-2920-1https://bugs.chromium.org/p/chromium/issues/detail?id=542060https://code.google.com/p/chromium/issues/detail?id=591402https://codereview.chromium.org/1454003003/
2016-03-06
Published