5.3
CVE-2017-18016
- EPSS 5.48%
- Veröffentlicht 11.01.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:19:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin).
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.48% | 0.917 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
http://www.openwall.com/lists/oss-security/2018/01/10/1
https://github.com/paritytech/parity/commit/53609f703e2f1af76441344ac3b72811c726a215
https://github.com/tintinweb/pub/tree/master/pocs/cve-2017-18016
https://www.exploit-db.com/exploits/43499/