The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Jul 20, 2014 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Jul 28, 2014 | Jul 16, 2014 |
| Suse | — | Upgrade chromium | Dec 18, 2015 | Jul 20, 2014 |
| Ubuntu | — | Upgrade oxideqt-codecs-extraUpgrade liboxideqtcore0Upgrade oxideqt-codecs | Nov 8, 2024 | Jul 20, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub