Vulnerability Name: | CVE-2016-1617 (CCN-110000) | ||||||||||||||||||||||||||||
Assigned: | 2016-01-20 | ||||||||||||||||||||||||||||
Published: | 2016-01-20 | ||||||||||||||||||||||||||||
Updated: | 2016-12-07 | ||||||||||||||||||||||||||||
Summary: | The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply ws policies to wss URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) 3.8 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-1617 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2016/01/stable-channel-update_20.html Source: SUSE Type: UNKNOWN openSUSE-SU-2016:0249 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:0250 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:0271 Source: CCN Type: RHSA-2016-0072 Important: chromium-browser security update Source: REDHAT Type: UNKNOWN RHSA-2016:0072 Source: DEBIAN Type: UNKNOWN DSA-3456 Source: BID Type: UNKNOWN 81430 Source: CCN Type: BID-81430 Google Chrome Prior to 48.0.2564.82 Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1034801 Source: UBUNTU Type: UNKNOWN USN-2877-1 Source: CONFIRM Type: UNKNOWN https://code.google.com/p/chromium/issues/detail?id=544765 Source: CONFIRM Type: UNKNOWN https://codereview.chromium.org/1455973003 Source: XF Type: UNKNOWN google-chrome-cve20161617-info-disc(110000) Source: GENTOO Type: UNKNOWN GLSA-201603-09 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-1617 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |