CVE-2016-5133Improper Authentication in Google Chrome

Severity
5.3MEDIUMNVD
OSV8.8
EPSS
0.7%
top 29.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 17

Description

Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server data stream.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages1 packages

NVDgoogle/chrome51.0.2704.106

🔴Vulnerability Details

3
GHSA
GHSA-95wh-v6qf-2wcw: Google Chrome before 522022-05-17
OSV
oxide-qt vulnerabilities2016-08-05
OSV
CVE-2016-5133: Google Chrome before 522016-07-23

📋Vendor Advisories

2
Ubuntu
Oxide vulnerabilities2016-08-05
Red Hat
chromium-browser: origin confusion in proxy authentication2016-07-20

💬Community

1
Bugzilla
CVE-2016-5133 chromium-browser: origin confusion in proxy authentication2016-07-21