CVE-2023-1227
published 2023-03-07CVE-2023-1227: Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to…
PriorityP343high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.46%
37.3th percentile
Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 111.0.5563.64-1~deb11u1 | 111.0.5563.64-1~deb11u1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| chromium | chromium | >= 0 < 111.0.5563.64-1 | 111.0.5563.64-1 |
| debian | chromium | < chromium 111.0.5563.64-1 (bookworm) | chromium 111.0.5563.64-1 (bookworm) |
| chrome | < 111.0.5563.64 | 111.0.5563.64 | |
| chrome | >= 111.0.5563.64 < 111.0.5563.64 | 111.0.5563.64 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
ghsa·2023-09-06
CVE-2023-41933 [HIGH] CWE-611 Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
GHSA
XSS vulnerability in Jenkins Job Configuration History Plugin
ghsa·2023-09-06
CVE-2023-41931 [MEDIUM] CWE-79 XSS vulnerability in Jenkins Job Configuration History Plugin
XSS vulnerability in Jenkins Job Configuration History Plugin
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timestamp value from history entries when rendering a history entry on the history view, resulting in a stored cross-site scripting (XSS) vulnerability.
GHSA
Path traversal in Jenkins Job Configuration History Plugin
ghsa·2023-09-06
CVE-2023-41930 [MEDIUM] CWE-22 Path traversal in Jenkins Job Configuration History Plugin
Path traversal in Jenkins Job Configuration History Plugin
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
GHSA
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
ghsa·2023-09-06
CVE-2023-41932 [MEDIUM] CWE-611 Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
GHSA
GHSA-jh2x-5f5p-c896: Use after free in Core in Google Chrome on Lacros prior to 111
ghsa_unreviewed·2023-03-08
CVE-2023-1227 [HIGH] CWE-416 GHSA-jh2x-5f5p-c896: Use after free in Core in Google Chrome on Lacros prior to 111
Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
OSV
CVE-2023-1227: Use after free in Core in Google Chrome on Lacros prior to 111
osv·2023-03-07·CVSS 8.8
CVE-2023-1227 [HIGH] CVE-2023-1227: Use after free in Core in Google Chrome on Lacros prior to 111
Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-1227
vendor_chrome·2023-03-09·CVSS 8.8
CVE-2023-1227 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2023-1227
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2023-1227
Chrome
Stable Channel Update for Desktop: CVE-2023-1225
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1225 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1225
Stable Channel Update for Desktop
CVE-2023-1225: Insufficient policy enforcement in Navigation. Reported by Roberto Ffrench-Davis @Lihaft on 2023-01-20 [$3000][ 1013080 ] Medium CVE-2023-1226: Insufficient policy enforcement in Web Payments API
Reported by Anonymous on 2019-10-10 [$3000][ 1348791 ] Medium CVE-2023-1227: Use after free in Core
Severity: medium
Debian
CVE-2023-1227: chromium - Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed...
vendor_debian·2023·CVSS 8.8
CVE-2023-1227 [HIGH] CVE-2023-1227: chromium - Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed...
Use after free in Core in Google Chrome on Lacros prior to 111.0.5563.64 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 111.0.5563.64-1)
bullseye: resolved (fixed in 111.0.5563.64-1~deb11u1)
forky: resolved (fixed in 111.0.5563.64-1)
sid: resolved (fixed in 111.0.5563.64-1)
trixie: resolved (fixed in 111.0.5563.64-1)
No detection rules found.
No public exploits indexed.
2023-03-07
Published