CVE-2018-18350
published 2018-12-11CVE-2018-18350: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security…
PriorityP429medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
1.38%
68.9th percentile
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| debian | chromium | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| debian | debian_linux | — | — |
| chrome | < 71.0.3578.80 | 71.0.3578.80 | |
| chrome | >= unspecified < 71.0.3578.80 | 71.0.3578.80 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93c8-wm3x-8xw6: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71
ghsa_unreviewed·2022-05-13
CVE-2018-18350 [MEDIUM] GHSA-93c8-wm3x-8xw6: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
OSV
CVE-2018-18350: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71
osv·2018-12-11·CVSS 6.5
CVE-2018-18350 [MEDIUM] CVE-2018-18350: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in Blink
vendor_redhat·2018-12-04·CVSS 6.5
CVE-2018-18350 [MEDIUM] chromium-browser: Insufficient policy enforcement in Blink
chromium-browser: Insufficient policy enforcement in Blink
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Debian
CVE-2018-18350: chromium - Incorrect handling of CSP enforcement during navigations in Blink in Google Chro...
vendor_debian·2018·CVSS 6.5
CVE-2018-18350 [MEDIUM] CVE-2018-18350: chromium - Incorrect handling of CSP enforcement during navigations in Blink in Google Chro...
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed in 71.0.3578.80-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/799747https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/799747https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352
2018-12-11
Published