Directory Traversal Affecting chromium package, versions <100.0.4896.60-1
Snyk CVSS
Attack Complexity
Low
User Interaction
Required
Confidentiality
High
Threat Intelligence
EPSS
0.1% (41st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-CHROMIUM-2436814
- published 31 Mar 2022
- disclosed 23 Jul 2022
Introduced: 31 Mar 2022
CVE-2022-1128 Open this link in a new tabHow to fix?
Upgrade Debian:unstable
chromium
to version 100.0.4896.60-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream chromium
package and not the chromium
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.