5.3

CVE-2017-18016

Exploit
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ParityBrowser Version1.6.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.48% 0.917
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

http://www.openwall.com/lists/oss-security/2018/01/10/1
Third Party Advisory
Exploit
Mailing List
https://github.com/paritytech/parity/commit/53609f703e2f1af76441344ac3b72811c726a215
Patch
Third Party Advisory
https://github.com/tintinweb/pub/tree/master/pocs/cve-2017-18016
Third Party Advisory
Exploit
Technical Description
https://www.exploit-db.com/exploits/43499/
Third Party Advisory
Exploit
VDB Entry