Vulnerability Name: | CVE-2015-1300 (CCN-106008) | ||||||||||||||||||||||||||||||||
Assigned: | 2015-09-01 | ||||||||||||||||||||||||||||||||
Published: | 2015-09-01 | ||||||||||||||||||||||||||||||||
Updated: | 2016-12-22 | ||||||||||||||||||||||||||||||||
Summary: | The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a history.back call. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) 3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-254 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1300 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Patch, Vendor Advisory http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1586 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:1873 Source: REDHAT Type: UNKNOWN RHSA-2015:1712 Source: DEBIAN Type: UNKNOWN DSA-3351 Source: SECTRACK Type: UNKNOWN 1033472 Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=511616 Source: XF Type: UNKNOWN google-chrome-cve20151300-info-disc(106008) Source: MISC Type: UNKNOWN https://github.com/w3c/resource-timing/issues/29 Source: GENTOO Type: UNKNOWN GLSA-201603-09 Source: CONFIRM Type: UNKNOWN https://src.chromium.org/viewvc/blink?revision=199553&view=revision Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-1300 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |