Cookie Exposure Vulnerability in Google Chrome for Multiple Platforms
CVE-2017-5042
5.7MEDIUM
Key Information:
- Vendor
- Vendor
- CVE Published:
- 24 April 2017
Summary
The vulnerability in Google Chrome allows an attacker on the local network to exploit SSDP to send arbitrary connections to URLs, capturing plaintext cookies sent by the browser. Users of Chrome versions before 57.0.2987.98 for Mac, Windows, and Linux, and versions before 57.0.2987.108 for Android are particularly at risk.
Affected Version(s)
Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved