CVE-2017-8504Sensitive Information Exposure in Corporation Microsoft Edge

Severity
4.3MEDIUMNVD
EPSS
12.7%
top 5.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 17

Description

Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8498.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hg64-q6m3-wv9w: Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Ed2022-05-17
GHSA
GHSA-cv8w-4mvf-w685: Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows Java2022-05-17

📋Vendor Advisories

1
Microsoft
Microsoft Edge Information Disclosure Vulnerability2017-06-13
CVE-2017-8504 — Sensitive Information Exposure | cvebase