CVE-2018-6051Cross-site Scripting in Google Chrome

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 31.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 14

Description

XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5google/chromeunspecified64.0.3282.119
NVDgoogle/chrome< 64.0.3282.119

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-mwmq-68qf-p3pw: XSS Auditor in Google Chrome prior to 642022-05-14
OSV
CVE-2018-6051: XSS Auditor in Google Chrome prior to 642018-09-25
CVEList
CVE-2018-6051: XSS Auditor in Google Chrome prior to 642018-09-25

📋Vendor Advisories

1
Red Hat
chromium-browser: referrer leak in xss auditor2018-01-24

💬Community

1
Bugzilla
CVE-2018-6051 chromium-browser: referrer leak in xss auditor2018-01-25
CVE-2018-6051 — Cross-site Scripting in Google Chrome | cvebase