CVE Database
/

CVE-2017-15387

Back to search

CVE-2017-15387

Published: Feb 7, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.

VendorProductVersions

n/a

Google Chrome prior to 62.0.3202.62

affected
Google Chrome prior to 62.0.3202.62

References

101482
vdb-entry
x_refsource_BID
https://crbug.com/756040
x_refsource_MISC
DSA-4020
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:2997
vendor-advisory
x_refsource_REDHAT
GLSA-201710-24
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now