CVE-2018-6082 — Sensitive Information Exposure in Google Chrome
Severity
4.7MEDIUMNVD
EPSS
0.7%
top 28.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 14
Latest updateMay 14
Description
Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages4 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSA▶
GHSA-3vpx-3wr3-2wf2: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65↗2022-05-14
OSV▶
CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65↗2018-11-14
CVEList▶
CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65↗2018-11-14