CVE-2018-18358
published 2018-12-11CVE-2018-18358: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on…
PriorityP421medium5.7CVSS 3.0
AVAACLPRNUIRSUCNIHAN
EPSS
0.44%
36.4th percentile
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| chromium | chromium | >= 0 < 71.0.3578.80-1 | 71.0.3578.80-1 |
| debian | chromium | < chromium 71.0.3578.80-1 (bookworm) | chromium 71.0.3578.80-1 (bookworm) |
| debian | debian_linux | — | — |
| chrome | < 71.0.3578.80 | 71.0.3578.80 | |
| chrome | >= unspecified < 71.0.3578.80 | 71.0.3578.80 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.7MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2qc-mfcw-3v2v: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71
ghsa_unreviewed·2022-05-14
CVE-2018-18358 [MEDIUM] CWE-20 GHSA-x2qc-mfcw-3v2v: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
OSV
CVE-2018-18358: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71
osv·2018-12-11·CVSS 5.7
CVE-2018-18358 [MEDIUM] CVE-2018-18358: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
Red Hat
chromium-browser: Insufficient policy enforcement in Proxy
vendor_redhat·2018-12-04·CVSS 5.7
CVE-2018-18358 [MEDIUM] chromium-browser: Insufficient policy enforcement in Proxy
chromium-browser: Insufficient policy enforcement in Proxy
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
Debian
CVE-2018-18358: chromium - Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0...
vendor_debian·2018·CVSS 5.7
CVE-2018-18358 [MEDIUM] CVE-2018-18358: chromium - Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0...
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
Scope: local
bookworm: resolved (fixed in 71.0.3578.80-1)
bullseye: resolved (fixed in 71.0.3578.80-1)
forky: resolved (fixed in 71.0.3578.80-1)
sid: resolved (fixed in 71.0.3578.80-1)
trixie: resolved (fixed in 71.0.3578.80-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/899126https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352http://www.securityfocus.com/bid/106084https://access.redhat.com/errata/RHSA-2018:3803https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.htmlhttps://crbug.com/899126https://security.gentoo.org/glsa/201908-18https://www.debian.org/security/2018/dsa-4352
2018-12-11
Published