Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-2164
HistoryJul 28, 2022 - 1:15 a.m.

CVE-2022-2164

2022-07-2801:15:17
Alpine Linux Development Team
security.alpinelinux.org
19
google chrome
extensions api
version 103.0.5060.53
insecure
discretionary access control
crafted html page
cve-2022-2164
unix

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

48.2%

Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.

OSVersionArchitecturePackageVersionFilename
Alpineedge-communitynoarchchromium< 103.0.5060.53-r0UNKNOWN
Alpine3.17-communitynoarchchromium< 103.0.5060.53-r0UNKNOWN
Alpine3.18-communitynoarchchromium< 103.0.5060.53-r0UNKNOWN
Alpine3.19-communitynoarchchromium< 103.0.5060.53-r0UNKNOWN
Alpine3.20-communitynoarchchromium< 103.0.5060.53-r0UNKNOWN

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

48.2%