Description
The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-3918 | The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in the case of a ServiceWorker fetch, which allows remote attackers to obtain sensitive information about visited web pages by reading CSP violation reports, related to FrameFetchContext.cpp and ResourceFetcher.cpp. |
Ubuntu USN |
USN-2920-1 | Oxide vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-05T23:32:21.330Z
Reserved: 2016-03-05T00:00:00.000Z
Link: CVE-2016-2845
No data.
Status : Modified
Published: 2016-03-06T02:59:15.867
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-2845
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN