CVE-2020-6501

Description

Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.092

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Google Chrome (x64) 80.0.3977.1Windows
Multiple vulnerabilities affected in Google Chrome 80.0.3977.1Windows
Multiple vulnerabilities affected in Google Chrome 80.0.3977.1 (For Debian)Linux
Multiple vulnerabilities affected in Google Chrome 80.0.3977.1 (For Centos)Linux
Multiple vulnerabilities affected in Google Chrome 80.0.3977.1 (For RedHat)Linux
Multiple vulnerabilities affected in Google Chrome 80.0.3977.1 (For Suse)Linux
Multiple vulnerabilities affected in Google Chrome 80.0.3977.1 (For Ubuntu)Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343228Google Chrome (x64) (131.0.6778.85, 131.0.6778.86)
PATCH-343227Google Chrome (131.0.6778.85, 131.0.6778.86)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234