CVE-2018-6089
04.12.2018, 17:29
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 < 66.0.3359.117 | |
redhat | linux_desktop | 6.0 |
redhat | linux_server | 6.0 |
redhat | linux_workstation | 6.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||
oxide-qt |
|
Common Weakness Enumeration
References