CVE-2021-30615Resource Exposure in Microsoft Edge Chromium

CWE-668Resource Exposure7 documents7 sources
Severity
6.5MEDIUMNVD
EPSS
8.4%
top 7.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateMay 24

Description

Chromium: CVE-2021-30615 Cross-origin data leak in Navigation

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Debianchromium/chromium< 93.0.4577.82-1+3
NVDmicrosoft/edge_chromium93.0.4577.63
NVDmicrosoft/edge93.0.961.38
CVEListV5microsoft/microsoft_edgeunspecified

Also affects: Fedora 35

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2wq3-r2pm-pwfm: Inappropriate implementation in Navigation in Google Chrome prior to 932022-05-24
CVEList
CVE-2021-30615: Chromium: CVE-2021-30615 Cross-origin data leak in Navigation2021-09-03
OSV
CVE-2021-30615: Chromium: CVE-2021-30615 Cross-origin data leak in Navigation2021-09-03

📋Vendor Advisories

3
Microsoft
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation2021-09-14
Chrome
Stable Channel Update for Desktop: CVE-2021-306152021-08-31
Debian
CVE-2021-30615: chromium - Chromium: CVE-2021-30615 Cross-origin data leak in Navigation2021