Cross-site request forgery in qutebrowser - CVE-2018-10895
Published: July 11, 2018 / Updated: July 16, 2018
Vulnerability identifier: #VU13875
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10895
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform CSRF attack on the qute://settings page.
The vulnerability exists due to insufficient CSRF protections. A remote attacker can supply 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, trick the victim into visiting a specially crafted website and execute arbitrary HTML and JavaScript code in victim's browser in context of vulnerable website.
The vulnerability exists due to insufficient CSRF protections. A remote attacker can supply 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, trick the victim into visiting a specially crafted website and execute arbitrary HTML and JavaScript code in victim's browser in context of vulnerable website.
Affected software
qutebrowser
Arch Linux
Opensuse
Fedora
qutebrowser
Arch Linux
Opensuse
Fedora
qutebrowser
How to mitigate CVE-2018-10895
Update to version 1.4.1.
qutebrowser - update to 1.4.1
qutebrowser - addressed in versions 1.4.1-1.fc27, 1.4.1-1.fc28
qutebrowser - addressed in versions 1.4.1-1.fc27, 1.4.1-1.fc28