PT-2018-17327 · Google+4 · Google Chrome+4
Tanner Emek
·
Published
2018-01-24
·
Updated
2024-06-15
·
CVE-2018-6052
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 64.0.3282.119
Description
The issue is related to a lack of support for a non-standard no-referrer policy value in Blink, which allowed a remote attacker to obtain referrer details from a web page that had opted out of sending referrer data. This could potentially reveal detailed information about links from a web page.
Recommendations
For Google Chrome versions prior to 64.0.3282.119, update to version 64.0.3282.119 or later to resolve the issue.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Opera
Red Hat
Suse