CVE-2016-2845
chromium-browser: CSP implementation in Blink does not ignore a URL's path component in the case of a ServiceWorker fetch
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
La implementación de la Content Security Policy (CSP) en Blink, tal como se utiliza en Google Chrome en versiones anteriores a 49.0.2623.75, no ignora un componente de ruta de URL en el caso de la recuperación de un ServiceWorker, lo que permite a atacantes remotos obtener información sensible sobre páginas web visitadas mediante la lectura de informes de violación de la CSP, relacionados con FrameFetchContext.cpp y ResourceFetcher.cpp.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-03-05 CVE Reserved
- 2016-03-06 CVE Published
- 2023-11-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html | X_refsource_confirm | |
http://homakov.blogspot.com/2014/01/using-content-security-policy-for-evil.html | X_refsource_misc | |
http://www.securityfocus.com/bid/84168 | Vdb Entry | |
http://www.securitytracker.com/id/1035185 | Vdb Entry | |
https://bugs.chromium.org/p/chromium/issues/detail?id=542060 | X_refsource_confirm | |
https://code.google.com/p/chromium/issues/detail?id=591402 | X_refsource_confirm | |
https://codereview.chromium.org/1454003003 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ubuntu.com/usn/USN-2920-1 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-2845 | 2016-03-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1315362 | 2016-03-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | <= 48.0.2564.116 Search vendor "Google" for product "Chrome" and version " <= 48.0.2564.116" | - |
Affected
|