CVE-2019-13669
published 2019-11-25CVE-2019-13669: Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a…
PriorityP417medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.65%
47.8th percentile
Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| debian | chromium | < chromium 78.0.3904.87-1 (bookworm) | chromium 78.0.3904.87-1 (bookworm) |
| chrome | < 77.0.3865.75 | 77.0.3865.75 | |
| chrome | >= unspecified < 77.0.3865.75 | 77.0.3865.75 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rv55-v2mj-w9hg: Incorrect data validation in navigation in Google Chrome prior to 77
ghsa_unreviewed·2022-05-24
CVE-2019-13669 [MEDIUM] GHSA-rv55-v2mj-w9hg: Incorrect data validation in navigation in Google Chrome prior to 77
Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
OSV
CVE-2019-13669: Incorrect data validation in navigation in Google Chrome prior to 77
osv·2019-11-25·CVSS 4.3
CVE-2019-13669 [MEDIUM] CVE-2019-13669: Incorrect data validation in navigation in Google Chrome prior to 77
Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Chrome
Stable Channel Update for Desktop: CVE-2019-13668
vendor_chrome·2019-09-10·CVSS 7.4
CVE-2019-13668 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13668
Stable Channel Update for Desktop
CVE-2019-13668: Global window leak via console. Reported by David Erceg on 2019-07-22
[$N/A][ 968451 ] Medium CVE-2019-13669: HTTP authentication spoof
Reported by Khalil Zhani on 2019-05-30
Severity: medium
Red Hat
chromium-browser: HTTP authentication spoof
vendor_redhat·2019-09-10·CVSS 4.3
CVE-2019-13669 [MEDIUM] chromium-browser: HTTP authentication spoof
chromium-browser: HTTP authentication spoof
Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Debian
CVE-2019-13669: chromium - Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 a...
vendor_debian·2019·CVSS 4.3
CVE-2019-13669 [MEDIUM] CVE-2019-13669: chromium - Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 a...
Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13669 chromium-browser: HTTP authentication spoof
bugzilla·2019-10-16·CVSS 4.3
CVE-2019-13669 [MEDIUM] CVE-2019-13669 chromium-browser: HTTP authentication spoof
CVE-2019-13669 chromium-browser: HTTP authentication spoof
The following flaw was identified in the Chromium browser: HTTP authentication spoof.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=968451
External References:
https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1762541]
Affects: fedora-all [bug 1762540]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:3211 https://access.redhat.com/errata/RHSA-2019:3211
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13669
---
Bugzilla
CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2
bugzilla·2019-10-16·CVSS 4.3
CVE-2019-13659 [MEDIUM] CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2
CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2019-13673 ... chromium: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2
bugzilla·2019-10-16·CVSS 4.3
CVE-2019-13659 [MEDIUM] CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2
CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2019-13673 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the releva
Bugzilla
CVE-2019-0193 solr: Remote Code Execution via DataImportHandler
bugzilla·2019-08-01·CVSS 7.2
CVE-2019-0193 [HIGH] CVE-2019-0193 solr: Remote Code Execution via DataImportHandler
CVE-2019-0193 solr: Remote Code Execution via DataImportHandler
The DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
References:
https://issues.apache.org/jira/browse/SOLR-13669
Discussion:
Created solr3 tracking bugs for this issue:
Affects: fedora-all [bug 1736775]
---
This vulnerability is out of security suppor
2019-11-25
Published