CVE-2022-1141
published 2022-07-23CVE-2022-1141: Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.81%
53.3th percentile
Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 100.0.4896.60-1~deb11u1 | 100.0.4896.60-1~deb11u1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| chromium | chromium | >= 0 < 100.0.4896.60-1 | 100.0.4896.60-1 |
| debian | chromium | < chromium 100.0.4896.60-1 (bookworm) | chromium 100.0.4896.60-1 (bookworm) |
| chrome | < 100.0.4896.60 | 100.0.4896.60 | |
| chrome | >= unspecified < 100.0.4896.60 | 100.0.4896.60 | |
| chrome_chrome | — | — | |
| log4js_project | log4js | >= 0 < 6.4.0 | 6.4.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Long Term Support Channel Update: CVE-2022-1131
vendor_chrome·2022-04-15·CVSS 8.8
CVE-2022-1131 [HIGH] Long Term Support Channel Update: CVE-2022-1131
Long Term Support Channel Update
CVE-2022-1131: Use after free in Cast UI. 1303253 Medium CVE-2022-1141: Use after free in File Manager
Severity: high
Debian
CVE-2022-1141: chromium - Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a...
vendor_debian·2022·CVSS 8.8
CVE-2022-1141 [HIGH] CVE-2022-1141: chromium - Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a...
Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
Scope: local
bookworm: resolved (fixed in 100.0.4896.60-1)
bullseye: resolved (fixed in 100.0.4896.60-1~deb11u1)
forky: resolved (fixed in 100.0.4896.60-1)
sid: resolved (fixed in 100.0.4896.60-1)
trixie: resolved (fixed in 100.0.4896.60-1)
GHSA
GHSA-3wr4-g3xj-q452: Use after free in File Manager in Google Chrome prior to 100
ghsa_unreviewed·2022-07-24
CVE-2022-1141 [HIGH] CWE-416 GHSA-3wr4-g3xj-q452: Use after free in File Manager in Google Chrome prior to 100
Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
OSV
CVE-2022-1141: Use after free in File Manager in Google Chrome prior to 100
osv·2022-07-23·CVSS 8.8
CVE-2022-1141 [HIGH] CVE-2022-1141: Use after free in File Manager in Google Chrome prior to 100
Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user gesture.
GHSA
Incorrect Default Permissions in log4js
ghsa·2022-01-21
CVE-2022-21704 [MEDIUM] CWE-276 Incorrect Default Permissions in log4js
Incorrect Default Permissions in log4js
### Impact
Default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config.
### Patches
Fixed by:
* https://github.com/log4js-node/log4js-node/pull/1141
* https://github.com/log4js-node/streamroller/pull/87
Released to NPM in [email protected]
### Workarounds
Every version of log4js published allows passing the mode parameter to the configuration of file appenders, see the documentation for details.
### References
Thanks to [ranjit-git](https://www.huntr.dev/users/ranjit-git) for raising the issue, and
No detection rules found.
No public exploits indexed.
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.htmlhttps://crbug.com/1303253https://security.gentoo.org/glsa/202208-25https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_29.htmlhttps://crbug.com/1303253https://security.gentoo.org/glsa/202208-25
2022-07-23
Published