CVE-2020-15959

EUVD-2020-7930
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
< 85.0.4183.102
opensusebackports_sle
15.0:sp1
opensusebackports_sle
15.0:sp2
opensuseleap
15.1
opensuseleap
15.2
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
chromium
bookworm
128.0.6613.84-1~deb12u1
fixed
bookworm (security)
130.0.6723.91-1~deb12u1
fixed
bullseye
120.0.6099.224-1~deb11u1
fixed
bullseye (security)
120.0.6099.224-1~deb11u1
fixed
sid
130.0.6723.91-2
fixed
trixie
129.0.6668.89-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
bionic
Fixed 85.0.4183.121-0ubuntu0.18.04.1
released
focal
not-affected
trusty
dne
xenial
Fixed 85.0.4183.121-0ubuntu0.16.04.1
released
References