CVE-2018-6082Sensitive Information Exposure in Google Chrome

Severity
4.7MEDIUMNVD
EPSS
0.7%
top 28.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 14

Description

Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-3vpx-3wr3-2wf2: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 652022-05-14
OSV
CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 652018-11-14
CVEList
CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 652018-11-14

📋Vendor Advisories

1
Red Hat
chromium-browser: circumvention of port blocking2018-03-06

💬Community

2
Bugzilla
qt5-qtwebengine: 16 security vulnerabilities2018-03-24
Bugzilla
CVE-2018-6082 chromium-browser: circumvention of port blocking2018-03-07
CVE-2018-6082 — Sensitive Information Exposure | cvebase