CVE-2021-38022
published 2021-12-23CVE-2021-38022: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.86%
54.3th percentile
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 97.0.4692.71-0.1~deb11u1 | 97.0.4692.71-0.1~deb11u1 |
| chromium | chromium | >= 0 < 97.0.4692.71-0.1 | 97.0.4692.71-0.1 |
| chromium | chromium | >= 0 < 97.0.4692.71-0.1 | 97.0.4692.71-0.1 |
| chromium | chromium | >= 0 < 97.0.4692.71-0.1 | 97.0.4692.71-0.1 |
| debian | chromium | < chromium 97.0.4692.71-0.1 (bookworm) | chromium 97.0.4692.71-0.1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 96.0.4664.45 | 96.0.4664.45 | |
| chrome | >= unspecified < 96.0.4664.45 | 96.0.4664.45 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2021-38022
vendor_chrome·2021-11-15·CVSS 6.5
CVE-2021-38022 [LOW] Stable Channel Update for Desktop: CVE-2021-38022
Stable Channel Update for Desktop
CVE-2021-38022: Inappropriate implementation in WebAuthentication. Reported by Michal Kepkowski on 2021-09-13 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: low
Microsoft
Chromium: CVE-2021-38022 Inappropriate implementation in WebAuthentication
vendor_msrc·2021-11-09·CVSS 6.5
CVE-2021-38022 [MEDIUM] Chromium: CVE-2021-38022 Inappropriate implementation in WebAuthentication
Chromium: CVE-2021-38022 Inappropriate implementation in WebAuthentication
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1954.29
11/19/2021
96.0.4664.45
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the versio
Debian
CVE-2021-38022: chromium - Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0...
vendor_debian·2021·CVSS 6.5
CVE-2021-38022 [MEDIUM] CVE-2021-38022: chromium - Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0...
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 97.0.4692.71-0.1)
bullseye: resolved (fixed in 97.0.4692.71-0.1~deb11u1)
forky: resolved (fixed in 97.0.4692.71-0.1)
sid: resolved (fixed in 97.0.4692.71-0.1)
trixie: resolved (fixed in 97.0.4692.71-0.1)
GHSA
GHSA-jpw9-fm6r-w3ph: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96
ghsa_unreviewed·2021-12-24
CVE-2021-38022 [MEDIUM] GHSA-jpw9-fm6r-w3ph: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
OSV
CVE-2021-38022: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96
osv·2021-12-23·CVSS 6.5
CVE-2021-38022 [MEDIUM] CVE-2021-38022: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Bugzilla
FIDO2/WebAuthn privacy leak through a timing attack using silent authentications.
bugzilla·2021-09-13
FIDO2/WebAuthn privacy leak through a timing attack using silent authentications.
FIDO2/WebAuthn privacy leak through a timing attack using silent authentications.
Created attachment 9240831
firefox-report.pdf
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:92.0) Gecko/20100101 Firefox/92.0
Steps to reproduce:
We identified a way to abuse WebAuthn/CTAP authentication that allows us to execute a timing attack which might lead to a serious privacy leak (e.g. account linking). The core of the issue are silent authentication calls (via CTAP) to authenticators. Silent authenticators are triggered when the allowCredentials list contains multiple key handles (credIDs). We tested a scenario where we compared the time response of invalid key handles (taken from different token) and key handles from the correct token but with a bad origin. The time difference is measur
arXiv
How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy
arxiv_fulltext·2022-05-17
How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy
[1][#1 --- michal]
[1]#1
[1]#1
[1]green Lucek: #1
[1][#1 ---dali]
[1][#1 ---ian]
[1]
Corresponding Author
51
55
key_handle
key_handles
uID
A
B
C
R
authenticatorGetAssertion
allowCredential
x[1]> 0ptp#1
*[1]Michal Kepkowski
[2]Lucjan Hanzlik
[3]Ian Wood
[4]Mohamed Ali Kaafar
[1]Macquarie University, E-mail: [email protected]
[2]CISPA Helmholtz Center for
Information Security, E-mail: [email protected]
[3]Macquarie University, E-mail: [email protected]
[4]Macquarie University, E-mail: [email protected]
How Not to Handle Keys:
Timing Attacks on FIDO Authenticator Privacy
## Abstract
This paper presents a timing attack on the FIDO2 (Fast IDentity Online) authentication protocol that allows attackers to link user accounts stored in vulnerable authenticators
https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.htmlhttps://crbug.com/1248862https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W46HRT2UVHWSLZB6JZHQF6JNQWKV744/https://www.debian.org/security/2022/dsa-5046https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.htmlhttps://crbug.com/1248862https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W46HRT2UVHWSLZB6JZHQF6JNQWKV744/https://www.debian.org/security/2022/dsa-5046
2021-12-23
Published