CVE-2020-4183
published 2020-06-04CVE-2020-4183: IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
PriorityP424medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.73%
50.4th percentile
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cog-creators | red-discordbot | >= 0 < 3.3.12 | 3.3.12 |
| ibm | security_guardium | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g25x-fggv-ww95: IBM Security Guardium 11
ghsa_unreviewed·2022-05-24
CVE-2020-4183 [MEDIUM] GHSA-g25x-fggv-ww95: IBM Security Guardium 11
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739.
GHSA
Remote Code Execution in Red Discord Bot
ghsa·2020-08-21
CVE-2020-15147 [HIGH] CWE-74 Remote Code Execution in Red Discord Bot
Remote Code Execution in Red Discord Bot
### Impact
A RCE exploit has been discovered in the Streams module: this exploit allows Discord users with specifically crafted "going live" messages to inject code into the Streams module's going live message. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information.
### Patches
This critical exploit has been fixed on version ``3.3.12`` & ``3.4``.
### Workarounds
Unloading the Streams module with ``unload streams`` can render this exploit not accessible. We still highly recommend updating to ``3.3.12`` or ``3.4`` to completely patch this issue.
### References
* https://github.com/Cog-Creators/Red-DiscordBot/pull/4183
### For more information
If you have any questions or comments about this advis
Red Hat
chromium-browser: Insufficient data validation in media
vendor_redhat·2020-09-21·CVSS 8.8
CVE-2020-15964 [HIGH] chromium-browser: Insufficient data validation in media
chromium-browser: Insufficient data validation in media
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in extensions
vendor_redhat·2020-09-21·CVSS 4.3
CVE-2020-15966 [MEDIUM] chromium-browser: Insufficient policy enforcement in extensions
chromium-browser: Insufficient policy enforcement in extensions
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
Red Hat
chromium-browser: Out of bounds write in V8
vendor_redhat·2020-09-21·CVSS 8.8
CVE-2020-15965 [HIGH] chromium-browser: Out of bounds write in V8
chromium-browser: Out of bounds write in V8
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in extensions
vendor_redhat·2020-09-21·CVSS 9.6
CVE-2020-15963 [CRITICAL] chromium-browser: Insufficient policy enforcement in extensions
chromium-browser: Insufficient policy enforcement in extensions
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Red Hat
chromium-browser: Out of bounds read in storage
vendor_redhat·2020-09-21·CVSS 8.8
CVE-2020-15960 [HIGH] chromium-browser: Out of bounds read in storage
chromium-browser: Out of bounds read in storage
Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in extensions
vendor_redhat·2020-09-21·CVSS 9.6
CVE-2020-15961 [CRITICAL] chromium-browser: Insufficient policy enforcement in extensions
chromium-browser: Insufficient policy enforcement in extensions
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
Red Hat
chromium-browser: Insufficient policy enforcement in serial
vendor_redhat·2020-09-21·CVSS 8.8
CVE-2020-15962 [HIGH] chromium-browser: Insufficient policy enforcement in serial
chromium-browser: Insufficient policy enforcement in serial
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Red Hat
chromium-browser: Use after free in offscreen canvas
vendor_redhat·2020-09-08·CVSS 8.8
CVE-2020-6576 [HIGH] chromium-browser: Use after free in offscreen canvas
chromium-browser: Use after free in offscreen canvas
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Use after free in video
vendor_redhat·2020-09-08·CVSS 9.6
CVE-2020-6573 [CRITICAL] chromium-browser: Use after free in video
chromium-browser: Use after free in video
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in installer
vendor_redhat·2020-09-08·CVSS 7.8
CVE-2020-6574 [HIGH] chromium-browser: Insufficient policy enforcement in installer
chromium-browser: Insufficient policy enforcement in installer
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
Red Hat
chromium-browser: Insufficient policy enforcement in networking
vendor_redhat·2020-09-08·CVSS 4.3
CVE-2020-15959 [MEDIUM] chromium-browser: Insufficient policy enforcement in networking
chromium-browser: Insufficient policy enforcement in networking
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
Red Hat
chromium-browser: Race in Mojo
vendor_redhat·2020-09-08·CVSS 8.3
CVE-2020-6575 [HIGH] chromium-browser: Race in Mojo
chromium-browser: Race in Mojo
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Red Hat
chromium-browser: Inappropriate implementation in Content Security Policy
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6561 [MEDIUM] CWE-358 chromium-browser: Inappropriate implementation in Content Security Policy
chromium-browser: Inappropriate implementation in Content Security Policy
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in Blink
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6562 [MEDIUM] chromium-browser: Insufficient policy enforcement in Blink
chromium-browser: Insufficient policy enforcement in Blink
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Incorrect security UI in Omnibox
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6565 [MEDIUM] chromium-browser: Incorrect security UI in Omnibox
chromium-browser: Incorrect security UI in Omnibox
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Red Hat
chromium-browser: Incorrect security UI in Omnibox
vendor_redhat·2020-08-25·CVSS 4.3
CVE-2020-6571 [MEDIUM] chromium-browser: Incorrect security UI in Omnibox
chromium-browser: Incorrect security UI in Omnibox
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Red Hat
chromium-browser: Incorrect security UI in permissions
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6564 [MEDIUM] chromium-browser: Incorrect security UI in permissions
chromium-browser: Incorrect security UI in permissions
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in iOS
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6558 [MEDIUM] chromium-browser: Insufficient policy enforcement in iOS
chromium-browser: Insufficient policy enforcement in iOS
Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Integer overflow in WebUSB
vendor_redhat·2020-08-25·CVSS 6.3
CVE-2020-6569 [MEDIUM] CWE-190 chromium-browser: Integer overflow in WebUSB
chromium-browser: Integer overflow in WebUSB
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in intent handling
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6563 [MEDIUM] chromium-browser: Insufficient policy enforcement in intent handling
chromium-browser: Insufficient policy enforcement in intent handling
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
Red Hat
chromium-browser: Insufficient validation of untrusted input in command line handling
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6567 [MEDIUM] CWE-20 chromium-browser: Insufficient validation of untrusted input in command line handling
chromium-browser: Insufficient validation of untrusted input in command line handling
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Red Hat
chromium-browser: Side-channel information leakage in WebRTC
vendor_redhat·2020-08-25·CVSS 4.3
CVE-2020-6570 [MEDIUM] CWE-203 chromium-browser: Side-channel information leakage in WebRTC
chromium-browser: Side-channel information leakage in WebRTC
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
Red Hat
chromium-browser: Insufficient policy enforcement in autofill
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6560 [MEDIUM] chromium-browser: Insufficient policy enforcement in autofill
chromium-browser: Insufficient policy enforcement in autofill
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in intent handling
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6568 [MEDIUM] chromium-browser: Insufficient policy enforcement in intent handling
chromium-browser: Insufficient policy enforcement in intent handling
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Red Hat
chromium-browser: Insufficient policy enforcement in media
vendor_redhat·2020-08-25·CVSS 6.5
CVE-2020-6566 [MEDIUM] chromium-browser: Insufficient policy enforcement in media
chromium-browser: Insufficient policy enforcement in media
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
No detection rules found.
No writeups or analysis indexed.
2020-06-04
Published