CVE Database
/

CVE-2017-5033

Back to search

CVE-2017-5033

Published: Apr 24, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword.

VendorProductVersions

n/a

Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android

affected
Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android

References

https://crbug.com/669086
x_refsource_CONFIRM
GLSA-201704-02
vendor-advisory
x_refsource_GENTOO
DSA-3810
vendor-advisory
x_refsource_DEBIAN
96767
vdb-entry
x_refsource_BID
RHSA-2017:0499
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now