Lucene search

K
cve[email protected]CVE-2022-4025
HistoryJan 02, 2023 - 11:15 p.m.

CVE-2022-4025

2023-01-0223:15:10
web.nvd.nist.gov
92
paint
google chrome
cve-2022-4025
data leak
security vulnerability

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

3.7 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%

Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome security severity: Low)

Affected configurations

Vulners
NVD
Node
googlechromeRange<98.0.4758.80

CNA Affected

[
  {
    "vendor": "Google",
    "product": "Chrome",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "98.0.4758.80",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

3.7 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.4%