openSUSE-SU-2020:1061Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00069.html CVE-2020-6519
MEDIUM
Chromium 83 - Full CSP Bypass
Record summary
CVE-2020-6519 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | Before 84.0.4147.89 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBChromium 83 - Full CSP BypassExploitDB exploitby Gal WeizmanNot analyzed1 file
References
Showing 12 of 14openSUSE-SU-2020:1148Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00007.html openSUSE-SU-2020:1172Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00018.html openSUSE-SU-2020:1048Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00041.html packetstormsecurity.com
http://packetstormsecurity.com/files/160353/Chromium-83-CSP-Bypass.html chromereleases.googleblog.com
https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop.html crbug.com
https://crbug.com/1064676 FEDORA-2020-bf684961d9Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTRPPTKZ2RKVH2XGQCWNFZ7FOGQ5LLCA FEDORA-2020-84d87cbd50Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYIDWCHG24ZTFD4P42D4A4WWPPA74BCG lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTRPPTKZ2RKVH2XGQCWNFZ7FOGQ5LLCA lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MYIDWCHG24ZTFD4P42D4A4WWPPA74BCG nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-6519