CVE-2018-6051
published 2018-09-25CVE-2018-6051: XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote…
PriorityP417medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
1.29%
67.4th percentile
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 64.0.3282.119 | 64.0.3282.119 | |
| chrome | >= unspecified < 64.0.3282.119 | 64.0.3282.119 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwmq-68qf-p3pw: XSS Auditor in Google Chrome prior to 64
ghsa_unreviewed·2022-05-14
CVE-2018-6051 [MEDIUM] CWE-79 GHSA-mwmq-68qf-p3pw: XSS Auditor in Google Chrome prior to 64
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
OSV
CVE-2018-6051: XSS Auditor in Google Chrome prior to 64
osv·2018-09-25·CVSS 4.3
CVE-2018-6051 [MEDIUM] CVE-2018-6051: XSS Auditor in Google Chrome prior to 64
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
Red Hat
chromium-browser: referrer leak in xss auditor
vendor_redhat·2018-01-24·CVSS 4.3
CVE-2018-6051 [MEDIUM] chromium-browser: referrer leak in xss auditor
chromium-browser: referrer leak in xss auditor
XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102797http://www.securitytracker.com/id/1040282https://access.redhat.com/errata/RHSA-2018:0265https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/441275https://www.debian.org/security/2018/dsa-4103http://www.securityfocus.com/bid/102797http://www.securitytracker.com/id/1040282https://access.redhat.com/errata/RHSA-2018:0265https://chromereleases.googleblog.com/2018/01/stable-channel-update-for-desktop_24.htmlhttps://crbug.com/441275https://www.debian.org/security/2018/dsa-4103
2018-09-25
Published