chromereleases.googleblog.com
https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html CVE-2021-30538
MEDIUM
Google Chrome Incorrect Authorization
Record summary
CVE-2021-30538 has a selected CVSS score of 4.3 (medium).
Description
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List, VulnCheck | Before 91.0.4472.77 | affected |
References
8crbug.com
https://crbug.com/1115045 FEDORA-2021-ca58c57bdfVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ETMZL6IHCTCTREEL434BQ4THQ7EOHJ43 FEDORA-2021-f94dadff78Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PAT6EOXVQFE6JFMFQF4IKAOUQSHMHL54 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ETMZL6IHCTCTREEL434BQ4THQ7EOHJ43 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PAT6EOXVQFE6JFMFQF4IKAOUQSHMHL54 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-30538 GLSA-202107-06Vendor advisory
https://security.gentoo.org/glsa/202107-06