CVE-2023-2311
published 2023-07-29CVE-2023-2311: Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.58%
44.4th percentile
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 112.0.5615.49-2~deb11u2 | 112.0.5615.49-2~deb11u2 |
| chromium | chromium | >= 0 < 112.0.5615.49-1 | 112.0.5615.49-1 |
| chromium | chromium | >= 0 < 112.0.5615.49-1 | 112.0.5615.49-1 |
| chromium | chromium | >= 0 < 112.0.5615.49-1 | 112.0.5615.49-1 |
| debian | chromium | < chromium 112.0.5615.49-1 (bookworm) | chromium 112.0.5615.49-1 (bookworm) |
| chrome | < 112.0.5615.49 | 112.0.5615.49 | |
| chrome | >= 112.0.5615.49 < 112.0.5615.49 | 112.0.5615.49 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-2311: Insufficient policy enforcement in File System API in Google Chrome prior to 112
osv·2023-07-29·CVSS 6.5
CVE-2023-2311 [MEDIUM] CVE-2023-2311: Insufficient policy enforcement in File System API in Google Chrome prior to 112
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
GHSA
GHSA-9c59-hw33-w5gf: Insufficient policy enforcement in File System API in Google Chrome prior to 112
ghsa_unreviewed·2023-07-29
CVE-2023-2311 [MEDIUM] GHSA-9c59-hw33-w5gf: Insufficient policy enforcement in File System API in Google Chrome prior to 112
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Citrix
Citrix Session Recording Security Bulletin for CVE-2023-6184
vendor_citrix·2024-01-16·CVSS 7.2
CVE-2023-6184 [HIGH] CWE-913 Citrix Session Recording Security Bulletin for CVE-2023-6184
Citrix Session Recording Security Bulletin for CVE-2023-6184
Pre-requisites CWE CVE-2023-6184 An authenticated user can perform RCE Attacker must possess admin privileges to the Session Recording server CWE-913 Instructions Cloud Software Group strongly urges affected customers of Citrix Session Recording to install the relevant updated versions of Citrix Session Recording as soon their upgrade schedule permits: Current Release (CR) Citrix Virtual Apps and Desktops 2311 and later Long Term Service Release (LTSR) Citrix Virtual Apps and Desktops 1912 LTSR CU8 hotfix 19.12.8100.4* and later Citrix Virtual Apps and Desktops 2203 LTSR CU4 and later Please use the following link for downloading the builds: https://www.citrix.com/downloads/ * Citrix Virtual Apps and Desktops 1912 LTSR CU8 hotfi
Chrome
Stable Channel Update for Desktop: CVE-2023-2311
vendor_chrome·2023-04-04·CVSS 8.8
CVE-2023-2311 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-2311
Stable Channel Update for Desktop
CVE-2023-2311: Insufficient policy enforcement in File System API. Reported by Axel Chong on 2022-08-19 [$NA][ 1223346 ] Medium CVE-2023-1818: Use after free in Vulkan
Reported by Abdulrahman Alqabandi, Microsoft Browser Vulnerability Research, Eric Lawrence, Microsoft, Patrick Walker (@HomeSen), and Kirtikumar Anandrao Ramchandani on 2021-06-24 [$NA][ 1406588 ] Medium CVE-2023-1819: Out of bounds read in Accessibility
Severity: medium
Debian
CVE-2023-2311: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 112...
vendor_debian·2023·CVSS 6.5
CVE-2023-2311 [MEDIUM] CVE-2023-2311: chromium - Insufficient policy enforcement in File System API in Google Chrome prior to 112...
Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 112.0.5615.49-1)
bullseye: resolved (fixed in 112.0.5615.49-2~deb11u2)
forky: resolved (fixed in 112.0.5615.49-1)
sid: resolved (fixed in 112.0.5615.49-1)
trixie: resolved (fixed in 112.0.5615.49-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/1354505https://lists.fedoraproject.org/archives/list/[email protected]/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/B6SAST6CB5KKCQKH75ER2UQ3ICYPHCIZ/https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop.htmlhttps://crbug.com/1354505https://lists.fedoraproject.org/archives/list/[email protected]/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/B6SAST6CB5KKCQKH75ER2UQ3ICYPHCIZ/
2023-07-29
Published