8.1

CVE-2019-6251

Exploit

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnomeEpiphany Version <= 3.31.4
WebkitgtkWebkitgtk Version < 2.24.1
WpewebkitWpe Webkit Version < 2.24.1
FedoraprojectFedora Version28
FedoraprojectFedora Version29
FedoraprojectFedora Version30
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version18.10
OpensuseLeap Version15.0
OpensuseLeap Version42.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.54% 0.848
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
https://seclists.org/bugtraq/2019/Apr/21
Third Party Advisory
Mailing List
https://bugs.webkit.org/show_bug.cgi?id=194208
Vendor Advisory
Issue Tracking
https://gitlab.gnome.org/GNOME/epiphany/issues/532
Patch
Third Party Advisory
Exploit
https://usn.ubuntu.com/3948-1/
Third Party Advisory