CVE-2020-2544
published 2020-01-15CVE-2020-2544: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0…
PriorityP422medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.97%
58.3th percentile
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
| oracle_corporation | weblogic_server | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_oracle4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7jjr-9r7c-2mwx: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
ghsa_unreviewed·2022-05-24
CVE-2020-2544 [MEDIUM] GHSA-7jjr-9r7c-2mwx: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Console — CVE-2020-2544
vendor_oracle·2020-01-15·CVSS 4.3
CVE-2020-2544 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Console — CVE-2020-2544
Oracle Oracle Fusion Middleware Risk Matrix: Console vulnerability
CVE: CVE-2020-2544
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6494 chromium-browser: Incorrect security UI in payments
bugzilla·2020-06-05·CVSS 6.5
CVE-2020-6494 [MEDIUM] CVE-2020-6494 chromium-browser: Incorrect security UI in payments
CVE-2020-6494 chromium-browser: Incorrect security UI in payments
An incorrect security ui flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1083972
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1844563]
Affects: fedora-all [bug 1844562]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-20
Bugzilla
CVE-2020-6495 chromium-browser: Insufficient policy enforcement in developer tools
bugzilla·2020-06-05·CVSS 6.5
CVE-2020-6495 [MEDIUM] CVE-2020-6495 chromium-browser: Insufficient policy enforcement in developer tools
CVE-2020-6495 chromium-browser: Insufficient policy enforcement in developer tools
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1072116
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1844563]
Affects: fedora-all [bug 1844562]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://acc
Bugzilla
CVE-2020-6496 chromium-browser: Use after free in payments
bugzilla·2020-06-05·CVSS 8.8
CVE-2020-6496 [HIGH] CVE-2020-6496 chromium-browser: Use after free in payments
CVE-2020-6496 chromium-browser: Use after free in payments
An use after free flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1085990
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1844563]
Affects: fedora-all [bug 1844562]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6496
Bugzilla
CVE-2020-6493 chromium-browser: Use after free in WebAuthentication
bugzilla·2020-06-05·CVSS 9.6
CVE-2020-6493 [CRITICAL] CVE-2020-6493 chromium-browser: Use after free in WebAuthentication
CVE-2020-6493 chromium-browser: Use after free in WebAuthentication
An use after free flaw was found in the WebAuthentication component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1082105
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1844563]
Affects: fedora-all [bug 1844562]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cv
Bugzilla
CVE-2020-6480 chromium-browser: Insufficient policy enforcement in enterprise
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6480 [MEDIUM] CVE-2020-6480 chromium-browser: Insufficient policy enforcement in enterprise
CVE-2020-6480 chromium-browser: Insufficient policy enforcement in enterprise
An insufficient policy enforcement flaw was found in the enterprise component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1054966
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.red
Bugzilla
CVE-2020-6472 chromium-browser: Insufficient policy enforcement in developer tools
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6472 [MEDIUM] CVE-2020-6472 chromium-browser: Insufficient policy enforcement in developer tools
CVE-2020-6472 chromium-browser: Insufficient policy enforcement in developer tools
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1064519
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6490 chromium-browser: Insufficient data validation in loader
bugzilla·2020-05-20·CVSS 4.3
CVE-2020-6490 [MEDIUM] CVE-2020-6490 chromium-browser: Insufficient data validation in loader
CVE-2020-6490 chromium-browser: Insufficient data validation in loader
An insufficient data validation flaw was found in the loader component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1035887
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/securi
Bugzilla
CVE-2020-6473 chromium-browser: Insufficient policy enforcement in Blink
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6473 [MEDIUM] CVE-2020-6473 chromium-browser: Insufficient policy enforcement in Blink
CVE-2020-6473 chromium-browser: Insufficient policy enforcement in Blink
An insufficient policy enforcement flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1049510
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/se
Bugzilla
CVE-2020-6467 chromium-browser: Use after free in WebRTC
bugzilla·2020-05-20·CVSS 8.8
CVE-2020-6467 [HIGH] CVE-2020-6467 chromium-browser: Use after free in WebRTC
CVE-2020-6467 chromium-browser: Use after free in WebRTC
An use after free flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1068084
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6467
Bugzilla
CVE-2020-6487 chromium-browser: Insufficient policy enforcement in downloads
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6487 [MEDIUM] CVE-2020-6487 chromium-browser: Insufficient policy enforcement in downloads
CVE-2020-6487 chromium-browser: Insufficient policy enforcement in downloads
An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=539938
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat
Bugzilla
CVE-2020-6475 chromium-browser: Incorrect security UI in full screen
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6475 [MEDIUM] CVE-2020-6475 chromium-browser: Incorrect security UI in full screen
CVE-2020-6475 chromium-browser: Incorrect security UI in full screen
An incorrect security ui flaw was found in the full screen component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1020026
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/c
Bugzilla
CVE-2020-6482 chromium-browser: Insufficient policy enforcement in developer tools
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6482 [MEDIUM] CVE-2020-6482 chromium-browser: Insufficient policy enforcement in developer tools
CVE-2020-6482 chromium-browser: Insufficient policy enforcement in developer tools
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=795595
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://a
Bugzilla
CVE-2020-6488 chromium-browser: Insufficient policy enforcement in downloads
bugzilla·2020-05-20·CVSS 4.3
CVE-2020-6488 [MEDIUM] CVE-2020-6488 chromium-browser: Insufficient policy enforcement in downloads
CVE-2020-6488 chromium-browser: Insufficient policy enforcement in downloads
An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1044277
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-6481 chromium-browser: Insufficient policy enforcement in URL formatting
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6481 [MEDIUM] CVE-2020-6481 chromium-browser: Insufficient policy enforcement in URL formatting
CVE-2020-6481 chromium-browser: Insufficient policy enforcement in URL formatting
An insufficient policy enforcement flaw was found in the URL formatting component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1068531
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://ac
Bugzilla
CVE-2020-6483 chromium-browser: Insufficient policy enforcement in payments
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6483 [MEDIUM] CVE-2020-6483 chromium-browser: Insufficient policy enforcement in payments
CVE-2020-6483 chromium-browser: Insufficient policy enforcement in payments
An insufficient policy enforcement flaw was found in the payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=966507
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.c
Bugzilla
CVE-2020-6474 chromium-browser: Use after free in Blink
bugzilla·2020-05-20·CVSS 8.8
CVE-2020-6474 [HIGH] CVE-2020-6474 chromium-browser: Use after free in Blink
CVE-2020-6474 chromium-browser: Use after free in Blink
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1059533
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6474
Bugzilla
CVE-2020-6468 chromium-browser: Type Confusion in V8
bugzilla·2020-05-20·CVSS 8.8
CVE-2020-6468 [HIGH] CVE-2020-6468 chromium-browser: Type Confusion in V8
CVE-2020-6468 chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1076708
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6468
Bugzilla
CVE-2020-6479 chromium-browser: Inappropriate implementation in sharing
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6479 [MEDIUM] CVE-2020-6479 chromium-browser: Inappropriate implementation in sharing
CVE-2020-6479 chromium-browser: Inappropriate implementation in sharing
An inappropriate implementation flaw was found in the sharing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1041749
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837931]
Affects: fedora-all [bug 1837930]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/secu
Bugzilla
CVE-2020-6478 chromium-browser: Inappropriate implementation in full screen
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6478 [MEDIUM] CVE-2020-6478 chromium-browser: Inappropriate implementation in full screen
CVE-2020-6478 chromium-browser: Inappropriate implementation in full screen
An inappropriate implementation flaw was found in the full screen component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1037730
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.
Bugzilla
CVE-2020-6465 chromium-browser: Use after free in reader mode
bugzilla·2020-05-20·CVSS 9.6
CVE-2020-6465 [CRITICAL] CVE-2020-6465 chromium-browser: Use after free in reader mode
CVE-2020-6465 chromium-browser: Use after free in reader mode
An use after free flaw was found in the reader mode component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1073015
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-64
Bugzilla
CVE-2020-6485 chromium-browser: Insufficient data validation in media router
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6485 [MEDIUM] CVE-2020-6485 chromium-browser: Insufficient data validation in media router
CVE-2020-6485 chromium-browser: Insufficient data validation in media router
An insufficient data validation flaw was found in the media router component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1047285
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-6471 chromium-browser: Insufficient policy enforcement in developer tools
bugzilla·2020-05-20·CVSS 9.6
CVE-2020-6471 [CRITICAL] CVE-2020-6471 chromium-browser: Insufficient policy enforcement in developer tools
CVE-2020-6471 chromium-browser: Insufficient policy enforcement in developer tools
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1059577
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6484 chromium-browser: Insufficient data validation in ChromeDriver
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6484 [MEDIUM] CVE-2020-6484 chromium-browser: Insufficient data validation in ChromeDriver
CVE-2020-6484 chromium-browser: Insufficient data validation in ChromeDriver
An insufficient data validation flaw was found in the ChromeDriver component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1045787
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-6466 chromium-browser: Use after free in media
bugzilla·2020-05-20·CVSS 9.6
CVE-2020-6466 [CRITICAL] CVE-2020-6466 chromium-browser: Use after free in media
CVE-2020-6466 chromium-browser: Use after free in media
An use after free flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1074706
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6466
Bugzilla
CVE-2020-6491 chromium-browser: Incorrect security UI in site information
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6491 [MEDIUM] CVE-2020-6491 chromium-browser: Incorrect security UI in site information
CVE-2020-6491 chromium-browser: Incorrect security UI in site information
An incorrect security ui flaw was found in the site information component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1050011
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/
Bugzilla
CVE-2020-6470 chromium-browser: Insufficient validation of untrusted input in clipboard
bugzilla·2020-05-20·CVSS 6.1
CVE-2020-6470 [MEDIUM] CVE-2020-6470 chromium-browser: Insufficient validation of untrusted input in clipboard
CVE-2020-6470 chromium-browser: Insufficient validation of untrusted input in clipboard
An insufficient validation of untrusted input flaw was found in the clipboard component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1065761
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
Bugzilla
CVE-2020-6469 chromium-browser: Insufficient policy enforcement in developer tools
bugzilla·2020-05-20·CVSS 9.6
CVE-2020-6469 [CRITICAL] CVE-2020-6469 chromium-browser: Insufficient policy enforcement in developer tools
CVE-2020-6469 chromium-browser: Insufficient policy enforcement in developer tools
An insufficient policy enforcement flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1067382
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837909]
Affects: fedora-all [bug 1837908]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://
Bugzilla
CVE-2020-6476 chromium-browser: Insufficient policy enforcement in tab strip
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6476 [MEDIUM] CVE-2020-6476 chromium-browser: Insufficient policy enforcement in tab strip
CVE-2020-6476 chromium-browser: Insufficient policy enforcement in tab strip
An insufficient policy enforcement flaw was found in the tab strip component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1035315
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837917]
Affects: fedora-all [bug 1837914]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-6489 chromium-browser: Inappropriate implementation in developer tools
bugzilla·2020-05-20·CVSS 4.3
CVE-2020-6489 [MEDIUM] CVE-2020-6489 chromium-browser: Inappropriate implementation in developer tools
CVE-2020-6489 chromium-browser: Inappropriate implementation in developer tools
An inappropriate implementation flaw was found in the developer tools component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1050756
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access
Bugzilla
CVE-2020-6486 chromium-browser: Insufficient policy enforcement in navigations
bugzilla·2020-05-20·CVSS 6.5
CVE-2020-6486 [MEDIUM] CVE-2020-6486 chromium-browser: Insufficient policy enforcement in navigations
CVE-2020-6486 chromium-browser: Insufficient policy enforcement in navigations
An insufficient policy enforcement flaw was found in the navigations component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1055524
External References:
https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop_19.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1837905]
Affects: fedora-all [bug 1837904]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2544 https://access.redhat.com/errata/RHSA-2020:2544
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.r
2020-01-15
Published