CVE-2016-2845
MEDIUMGoogle Chrome < 48.0.2564.116 - Information Disclosure
Title source: ruleDescription
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
References (8)
Scores
CVSS v3
5.3
EPSS
0.0065
EPSS Percentile
70.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
Status
draft
Affected Products (1)
google/chrome
< 48.0.2564.116
Timeline
Published
Mar 06, 2016
Tracked Since
Feb 18, 2026