Vulnerability Name: | CVE-2010-0660 (CCN-55986) |
Assigned: | 2010-01-25 |
Published: | 2010-01-25 |
Updated: | 2017-09-19 |
Summary: | Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-200
|
Vulnerability Consequences: | Obtain Information |
References: | Source: CONFIRM Type: UNKNOWN http://code.google.com/p/chromium/issues/detail?id=29920
Source: MITRE Type: CNA CVE-2010-0660
Source: CCN Type: Google Chrome Releases Stable Channel Update
Source: CONFIRM Type: Patch http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html
Source: CCN Type: SA37769 Google Chrome Multiple Vulnerabilities
Source: CCN Type: SECTRACK ID: 1023506 Google Chrome Bugs Let Remote Users Execute Arbitrary Code, Deny Service, and Obtain Information.
Source: SECTRACK Type: UNKNOWN 1023506
Source: CONFIRM Type: Vendor Advisory http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
Source: CCN Type: OSVDB ID: 62312 Google Chrome Corner Case Referer Header Stripping Information Disclosure
Source: CCN Type: OSVDB ID: 65320 Apple Safari WebKit HTTP Site Redirect Referer Header Information Disclosure
Source: CCN Type: BID-37948 Google Chrome prior to 4.0.249.78 Multiple Security Vulnerabilities
Source: XF Type: UNKNOWN googlechrome-referer-info-disclosure(55986)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14247
|
Vulnerable Configuration: | Configuration 1: cpe:/a:google:chrome:0.2.149.27:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.149.29:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.149.30:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.152.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.153.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.3.154.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.3.154.3:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.18:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.22:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.31:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.4.154.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.36:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.39:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.42:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.43:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.46:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.48:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.52:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.53:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.59:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.65:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.156.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.157.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.157.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.158.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.159.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.169.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.169.1:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.170.0:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.8:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.27:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.28:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.30:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.31:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.37:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.38:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.182.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.190.2:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.193.2:beta:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.21:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.24:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.32:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version <= 4.0.249.0) Configuration CCN 1: cpe:/a:google:chrome:0.2.149.27:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.149.29:*:*:*:*:*:*:*OR cpe:/a:google:chrome:0.2.149.30:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.36:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.53:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.46:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.59:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.48:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.64:*:*:*:*:*:*:*OR cpe:/a:google:chrome:1.0.154.65:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.30:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.31:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.33:*:*:*:*:*:*:*OR cpe:/a:google:chrome:2.0.172.37:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.24:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.33:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
Definition ID | Class | Title | Last Modified |
---|
oval:org.mitre.oval:def:14247 | V | Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging. | 2014-04-07 |
|
BACK |