CVE-2020-6400
published 2020-02-11CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
2.00%
78.6th percentile
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| chromium | chromium | >= 0 < 80.0.3987.106-1 | 80.0.3987.106-1 |
| debian | chromium | < chromium 80.0.3987.106-1 (bookworm) | chromium 80.0.3987.106-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 80.0.3987.87 | 80.0.3987.87 | |
| chrome | >= unspecified < 80.0.3987.87 | 80.0.3987.87 | |
| chrome_chrome | — | — | |
| opensuse | backports_sle | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_cisco7.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mwm8-xq92-vxfq: Inappropriate implementation in CORS in Google Chrome prior to 80
ghsa_unreviewed·2022-05-24
CVE-2020-6400 [MEDIUM] CWE-200 GHSA-mwm8-xq92-vxfq: Inappropriate implementation in CORS in Google Chrome prior to 80
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
OSV
CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80
osv·2020-02-11·CVSS 6.5
CVE-2020-6400 [MEDIUM] CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Cisco
Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability
vendor_cisco·2020-02-26·CVSS 7.8
CVE-2020-3173 [HIGH] CWE-78 Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability
Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device.
The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by including crafted arguments to specific commands on the local management CLI. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the inject
Cisco
Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
vendor_cisco·2020-02-26·CVSS 7.8
CVE-2020-3171 [HIGH] CWE-78 Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are
Cisco
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
vendor_cisco·2020-02-26·CVSS 7.8
CVE-2020-3167 [HIGH] CWE-78 Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS).
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are executed with root privileges.
Cisco has released software updates th
Red Hat
chromium-browser: Inappropriate implementation in CORS
vendor_redhat·2020-02-04·CVSS 6.5
CVE-2020-6400 [MEDIUM] chromium-browser: Inappropriate implementation in CORS
chromium-browser: Inappropriate implementation in CORS
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Chrome
Stable Channel Update for Desktop: CVE-2020-6500
vendor_chrome·2020-02-04·CVSS 6.5
CVE-2020-6500 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6500
Stable Channel Update for Desktop
CVE-2020-6500: Inappropriate implementation in interstitials. Reported by evi1m0 of Bilibili Security Team on 2018-05-15
[$1000][ 1038036 ] Medium CVE-2020-6400: Inappropriate implementation in CORS
Reported by Takashi Yoneuchi (@y0n3uchy) on 2019-12-27
Severity: medium
Debian
CVE-2020-6400: chromium - Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allo...
vendor_debian·2020·CVSS 6.5
CVE-2020-6400 [MEDIUM] CVE-2020-6400: chromium - Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allo...
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 80.0.3987.106-1)
bullseye: resolved (fixed in 80.0.3987.106-1)
forky: resolved (fixed in 80.0.3987.106-1)
sid: resolved (fixed in 80.0.3987.106-1)
trixie: resolved (fixed in 80.0.3987.106-1)
Cisco
Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3171 Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
CVE-2020-3171: Cisco FXOS and UCS Manager Software Local Management CLI Command Injection Vulnerability
A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected
Cisco
Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3167 Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
CVE-2020-3167: Cisco FXOS and UCS Manager Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including crafted arguments to specific commands. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnects, the injected commands are executed with root privileges. Cisco has released softwa
Cisco
Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3173 Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability
CVE-2020-3173: Cisco UCS Manager Software Local Management CLI Command Injection Vulnerability
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnerability by including crafted arguments to specific commands on the local management CLI. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS with the privileges of the currently logged-in user for all affected platforms excluding Cisco UCS 6400 Series Fabric Interconnects. On Cisco UCS 6400 Series Fabric Interconnect
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.htmlhttps://access.redhat.com/errata/RHSA-2020:0514https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1038036https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/https://security.gentoo.org/glsa/202003-08https://www.debian.org/security/2020/dsa-4638http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-02/msg00025.htmlhttps://access.redhat.com/errata/RHSA-2020:0514https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1038036https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/https://security.gentoo.org/glsa/202003-08https://www.debian.org/security/2020/dsa-4638
2020-02-11
Published