Back to search
CVE-2017-5033
Published: Apr 24, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correctly propagate CSP restrictions to local scheme pages, which allowed a remote attacker to bypass content security policy via a crafted HTML page, related to the unsafe-inline keyword.
| Vendor | Product | Versions |
|---|---|---|
n/a | Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android | affected Google Chrome prior to 57.0.2987.98 for Mac, Windows and Linux, and 57.0.2987.108 for Android |
References
https://twitter.com/Ma7h1as/status/907641276434063361
x_refsource_MISC
https://crbug.com/669086
x_refsource_CONFIRM
GLSA-201704-02
vendor-advisory
x_refsource_GENTOO
DSA-3810
vendor-advisory
x_refsource_DEBIAN
96767
vdb-entry
x_refsource_BID
RHSA-2017:0499
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now