CVE-2018-6101
published 2018-12-04CVE-2018-6101: A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if…
PriorityP341high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
2.66%
84.1th percentile
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 66.0.3359.117 | 66.0.3359.117 | |
| chrome | >= unspecified < 66.0.3359.117 | 66.0.3359.117 | |
| redhat | linux_desktop | — | — |
| redhat | linux_server | — | — |
| redhat | linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Insufficient protection of remote debugging prototol in DevTools
vendor_redhat·2018-04-17·CVSS 7.5
CVE-2018-6101 [HIGH] chromium-browser: Insufficient protection of remote debugging prototol in DevTools
chromium-browser: Insufficient protection of remote debugging prototol in DevTools
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
GHSA
GHSA-cwr3-w8x8-8ff3: A lack of host validation in DevTools in Google Chrome prior to 66
ghsa_unreviewed·2022-05-14
CVE-2018-6101 [HIGH] CWE-20 GHSA-cwr3-w8x8-8ff3: A lack of host validation in DevTools in Google Chrome prior to 66
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
OSV
CVE-2018-6101: A lack of host validation in DevTools in Google Chrome prior to 66
osv·2018-12-04·CVSS 7.5
CVE-2018-6101 [HIGH] CVE-2018-6101: A lack of host validation in DevTools in Google Chrome prior to 66
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/813540https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182http://www.securityfocus.com/bid/103917https://access.redhat.com/errata/RHSA-2018:1195https://chromereleases.googleblog.com/2018/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/813540https://security.gentoo.org/glsa/201804-22https://www.debian.org/security/2018/dsa-4182
2018-12-04
Published