CVE-2018-8366
published 2018-09-13CVE-2018-8366: An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information…
PriorityP414low3.1CVSS 3.0
AVNACHPRNUIRSUCLINAN
EPSS
5.05%
91.4th percentile
An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_edge | — | — |
| microsoft | microsoft_edge | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1803_for_x64-based_systems | — | — |
CVSS provenance
nvdv3.03.1LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3qg-3g4c-5jwm: An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Inf
ghsa_unreviewed·2022-05-14
CVE-2018-8366 [LOW] CWE-200 GHSA-m3qg-3g4c-5jwm: An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Inf
An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge.
Microsoft
Microsoft Edge Information Disclosure Vulnerability
vendor_msrc·2018-09-11·CVSS 4.3
CVE-2018-8366 [LOW] Microsoft Edge Information Disclosure Vulnerability
Microsoft Edge Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type. An attacker could use the vulnerability to read the URL of a cross-origin request. Websites that that do not securely populate the URL with confidential information could allow information to be disclosed to an attacker.
To exploit the vulnerability, in a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, the user must be logged on to a website that does not securely populate URLs with confidential information. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attac
No detection rules found.
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilitiesMicrosoft released coverage for 17 critical bugs. Cisco Talos believes 16 of these are of special importance and n
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
## Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilities Microsoft released coverage for 17 critical bugs. Cisco Talos believ
Bugzilla
Stealing of URL cross-domain using performance.getEntries() once again, treat meta refresh channel as a redirect by setting result principal URL
bugzilla·2018-06-13
[MEDIUM] Stealing of URL cross-domain using performance.getEntries() once again, treat meta refresh channel as a redirect by setting result principal URL
Stealing of URL cross-domain using performance.getEntries() once again, treat meta refresh channel as a redirect by setting result principal URL
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.79 Safari/537.36
Steps to reproduce:
IMO, the fix for the following issue is incomplete: https://bugzilla.mozilla.org/show_bug.cgi?id=1246956
We can still access to the Cross-Origin URL, which should be blocked.
This issue has been found in Microsoft Edge too.
Proof Of Concept:
redireg.html:
setTimeout(function(){alert(performance.getEntriesByType("resource")[1].name)},5000);
Type anything into the address bar and press ENTER!
Then I'll figure out your secret search!
con.html:
histback.html:
history.back();
Test live o
http://www.securityfocus.com/bid/105253http://www.securitytracker.com/id/1041623https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8366http://www.securityfocus.com/bid/105253http://www.securitytracker.com/id/1041623https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8366
2018-09-13
Published