CVE-2023-0704
published 2023-02-07CVE-2023-0704: Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.88%
55.0th percentile
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 110.0.5481.77-1~deb11u1 | 110.0.5481.77-1~deb11u1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| debian | chromium | < chromium 110.0.5481.77-1 (bookworm) | chromium 110.0.5481.77-1 (bookworm) |
| chrome | < 110.0.5481.77 | 110.0.5481.77 | |
| chrome | >= unspecified < 110.0.5481.77 | 110.0.5481.77 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Chromium vulnerabilities
vendor_ubuntu·2023-02-21·CVSS 8.8
CVE-2023-0700 [HIGH] Chromium vulnerabilities
Title: Chromium vulnerabilities
Summary: Several security issues were fixed in Chromium.
It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)
It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)
It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of
Microsoft
Chromium: CVE-2023-0704 Insufficient policy enforcement in DevTools
vendor_msrc·2023-02-14·CVSS 6.5
CVE-2023-0704 [MEDIUM] Chromium: CVE-2023-0704 Insufficient policy enforcement in DevTools
Chromium: CVE-2023-0704 Insufficient policy enforcement in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microso
Chrome
Stable Channel Update for Desktop: CVE-2023-0702
vendor_chrome·2023-02-07·CVSS 8.8
CVE-2023-0702 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0702
Stable Channel Update for Desktop
CVE-2023-0702: Type Confusion in Data Transfer. Reported by Sri on 2022-04-14 [$1000][ 1405574 ] Medium CVE-2023-0703: Type Confusion in DevTools
Reported by raven at KunLun lab on 2023-01-07 [$2000][ 1385982 ] Low CVE-2023-0704: Insufficient policy enforcement in DevTools
Severity: medium
Debian
CVE-2023-0704: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481...
vendor_debian·2023·CVSS 6.5
CVE-2023-0704 [MEDIUM] CVE-2023-0704: chromium - Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481...
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in 110.0.5481.77-1)
sid: resolved (fixed in 110.0.5481.77-1)
trixie: resolved (fixed in 110.0.5481.77-1)
OSV
chromium-browser vulnerabilities
osv·2023-02-21·CVSS 8.8
CVE-2023-0471 [HIGH] chromium-browser vulnerabilities
chromium-browser vulnerabilities
It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)
It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)
It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of the Omnibox (URL bar) via a crafted HTML page.
(CVE-2023-
OSV
CVE-2023-0704: Insufficient policy enforcement in DevTools in Google Chrome prior to 110
osv·2023-02-07·CVSS 6.5
CVE-2023-0704 [MEDIUM] CVE-2023-0704: Insufficient policy enforcement in DevTools in Google Chrome prior to 110
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
GHSA
GHSA-9p67-jm42-x3f6: Insufficient policy enforcement in DevTools in Google Chrome prior to 110
ghsa_unreviewed·2023-02-07
CVE-2023-0704 [MEDIUM] CWE-602 GHSA-9p67-jm42-x3f6: Insufficient policy enforcement in DevTools in Google Chrome prior to 110
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-52813 kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET
bugzilla·2024-05-22·CVSS 5.5
CVE-2023-52813 [MEDIUM] CVE-2023-52813 kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET
CVE-2023-52813 kernel: crypto: pcrypt - Fix hungtask for PADATA_RESET
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix hungtask for PADATA_RESET
The Linux kernel CVE team has assigned CVE-2023-52813 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052103-CVE-2023-52813-0704@gregkh/T
Discussion:
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52813 is: CHECK Maybe valid. Check manually. with impact LOW (that is an approximation based on flags DANGER WARNONLY ; these flags parsed automatically based on patch data). Such automatic check happens only for Low/Moderates (and only when not from reporter, but parsing already existing CVE). Highs always checked manually (I check it
Bugzilla
Prevent /json/* pages from being loaded within an iframe
bugzilla·2023-04-06
CVE-2023-0704 Prevent /json/* pages from being loaded within an iframe
Prevent /json/* pages from being loaded within an iframe
To prevent leaking connection details for the HTTP endpoints of the CDP implementation to any particular website (see the [issue for Chromium](https://canvatechblog.com/discovering-headroll-cve-2023-0704-in-chromium-2e7f66fc130c)) we should stop loading the various `/json/*` pages within an iframe.
As discussed with Freddy on Slack this is mostly `sec-want` / `sec-low`. But I would like to get this fixed to not leak the details, which could be used for potential other security attacks.
Discussion:
Thinking about this some more, the `targetId` leaking through e.g., someone screenshotting an evil page (and then putting the json endpoints into an iframe) is probably a leak that we should plug, but definitely not so severe given that
https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1385982https://security.gentoo.org/glsa/202309-17https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1385982https://security.gentoo.org/glsa/202309-17
2023-02-07
Published