CVE-2018-18351
published 2018-12-11CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to…
PriorityP432medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
2.55%
83.4th percentile
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| debian | chromium | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| debian | debian_linux | — | — |
| chrome | < 71.0.3578.80 | 71.0.3578.80 | |
| chrome | >= unspecified < 71.0.3578.80 | 71.0.3578.80 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j8q6-cppq-xgq5: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71
ghsa_unreviewed·2022-05-14
CVE-2018-18351 [MEDIUM] CWE-20 GHSA-j8q6-cppq-xgq5: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
OSV
CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71
osv·2018-12-11·CVSS 6.5
CVE-2018-18351 [MEDIUM] CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in Navigation
vendor_redhat·2018-12-04·CVSS 6.5
CVE-2018-18351 [MEDIUM] chromium-browser: Insufficient policy enforcement in Navigation
chromium-browser: Insufficient policy enforcement in Navigation
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
Debian
CVE-2018-18351: chromium - Lack of proper validation of ancestor frames site when sending lax cookies in Na...
vendor_debian·2018·CVSS 6.5
CVE-2018-18351 [MEDIUM] CVE-2018-18351: chromium - Lack of proper validation of ancestor frames site when sending lax cookies in Na...
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed in 71.0.3578.80-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/833847https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/833847https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352
2018-12-11
Published