CVE-2018-18358

MEDIUM

Google Chrome < 71.0.3578.80 - Localhost Proxy via WPAD File

Title source: llm
STIX 2.1

Description

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

References (6)

Core 6
Core References
Issue Tracking x_refsource_misc
https://crbug.com/899126
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:3803
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4352
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106084
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201908-18

Scores

CVSS v3 5.7
EPSS 0.0011
EPSS Percentile 29.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (5)
debian/debian_linux 9.0
google/chrome < 71.0.3578.80
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_server 6.0
redhat/enterprise_linux_workstation 6.0
Published Dec 11, 2018
Tracked Since Feb 18, 2026