Lucene search

K
cve[email protected]CVE-2013-6634
HistoryDec 07, 2013 - 12:55 a.m.

CVE-2013-6634

2013-12-0700:55:03
CWE-287
web.nvd.nist.gov
45
cve
2013
6634
google chrome
session fixation
web sessions
http status code

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.5%

The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.

Affected configurations

NVD
Node
googlechromeRange31.0.1650.62
OR
googlechromeMatch31.0.1650.0
OR
googlechromeMatch31.0.1650.2
OR
googlechromeMatch31.0.1650.3
OR
googlechromeMatch31.0.1650.4
OR
googlechromeMatch31.0.1650.5
OR
googlechromeMatch31.0.1650.6
OR
googlechromeMatch31.0.1650.7
OR
googlechromeMatch31.0.1650.8
OR
googlechromeMatch31.0.1650.9
OR
googlechromeMatch31.0.1650.10
OR
googlechromeMatch31.0.1650.11
OR
googlechromeMatch31.0.1650.12
OR
googlechromeMatch31.0.1650.13
OR
googlechromeMatch31.0.1650.14
OR
googlechromeMatch31.0.1650.15
OR
googlechromeMatch31.0.1650.16
OR
googlechromeMatch31.0.1650.17
OR
googlechromeMatch31.0.1650.18
OR
googlechromeMatch31.0.1650.19
OR
googlechromeMatch31.0.1650.20
OR
googlechromeMatch31.0.1650.22
OR
googlechromeMatch31.0.1650.23
OR
googlechromeMatch31.0.1650.25
OR
googlechromeMatch31.0.1650.26
OR
googlechromeMatch31.0.1650.27
OR
googlechromeMatch31.0.1650.28
OR
googlechromeMatch31.0.1650.29
OR
googlechromeMatch31.0.1650.30
OR
googlechromeMatch31.0.1650.31
OR
googlechromeMatch31.0.1650.32
OR
googlechromeMatch31.0.1650.33
OR
googlechromeMatch31.0.1650.34
OR
googlechromeMatch31.0.1650.35
OR
googlechromeMatch31.0.1650.36
OR
googlechromeMatch31.0.1650.37
OR
googlechromeMatch31.0.1650.38
OR
googlechromeMatch31.0.1650.39
OR
googlechromeMatch31.0.1650.41
OR
googlechromeMatch31.0.1650.42
OR
googlechromeMatch31.0.1650.43
OR
googlechromeMatch31.0.1650.44
OR
googlechromeMatch31.0.1650.45
OR
googlechromeMatch31.0.1650.46
OR
googlechromeMatch31.0.1650.47
OR
googlechromeMatch31.0.1650.48
OR
googlechromeMatch31.0.1650.49
OR
googlechromeMatch31.0.1650.50
OR
googlechromeMatch31.0.1650.51
OR
googlechromeMatch31.0.1650.52
OR
googlechromeMatch31.0.1650.53
OR
googlechromeMatch31.0.1650.54
OR
googlechromeMatch31.0.1650.55
OR
googlechromeMatch31.0.1650.57
OR
googlechromeMatch31.0.1650.58
OR
googlechromeMatch31.0.1650.59
OR
googlechromeMatch31.0.1650.60
OR
googlechromeMatch31.0.1650.61

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6 Medium

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.5%