CVE-2020-4324
published 2020-09-23CVE-2020-4324: IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
1.24%
65.7th percentile
IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| ibm | security_secret_server | < 10.9 | 10.9 |
| ibm | security_secret_server | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv3.03.5LOWCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7g9j-7jq7-5chw: IBM Security Secret Server proir to 10
ghsa_unreviewed·2022-05-24
CVE-2020-4324 [MEDIUM] GHSA-7g9j-7jq7-5chw: IBM Security Secret Server proir to 10
IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improper input validation. IBM X-Force ID: 177515.
Chrome
Stable Channel Update for Desktop: CVE-2021-21228
vendor_chrome·2021-04-26·CVSS 4.3
CVE-2021-21228 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-21228
Stable Channel Update for Desktop
CVE-2021-21228: Insufficient policy enforcement in extensions. Reported by Rob Wu on 2020-10-16 [$5000][ 1193233 ] Medium CVE-2021-4324: Insufficient policy enforcement in Google Update
Reported by Abdelhamid Naceri (halov) on 2021-03-28 [$TBD][ 1198165 ] Medium CVE-2021-21229: Incorrect security UI in downloads
Severity: medium
Red Hat
Mozilla: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk
vendor_redhat·2021-01-06·CVSS 8.8
CVE-2020-16044 [HIGH] CWE-416 Mozilla: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk
Mozilla: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk
Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
Statement: Regarding Thunderbird: in general this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail, but it is potentially a risk in browser or browser-like contexts.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-23
Published