Lucene search

K
nvd[email protected]NVD:CVE-2019-6251
HistoryJan 14, 2019 - 8:29 a.m.

CVE-2019-6251

2019-01-1408:29:00
web.nvd.nist.gov
4

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

5.9

Confidence

Low

EPSS

0.01

Percentile

84.1%

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

Affected configurations

Nvd
Node
gnomeepiphanyRange≤3.31.4
Node
webkitgtkwebkitgtkRange<2.24.1
OR
wpewebkitwpe_webkitRange<2.24.1
Node
fedoraprojectfedoraMatch28
OR
fedoraprojectfedoraMatch29
OR
fedoraprojectfedoraMatch30
Node
canonicalubuntu_linuxMatch18.04lts
OR
canonicalubuntu_linuxMatch18.10
Node
opensuseleapMatch15.0
OR
opensuseleapMatch42.3

References

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

AI Score

5.9

Confidence

Low

EPSS

0.01

Percentile

84.1%