Overly permissive cross-domain whitelist in Adobe Flash Player - CVE-2019-8075
Published: September 27, 2019 / Updated: November 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass the CORS protection mechanism.
The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request in Adobe Flash player. A remote attacker can bypass implemented same origin policy restrictions and gain access to sensitive information from another domain.
Affected software
Fedora
chromium (Debian package)
chromium
Google Chrome
How to mitigate CVE-2019-8075
chromium (Debian package) - update to 87.0.4280.88-0.4~deb10u1
Google Chrome - update to 87.0.4280.66
chromium - addressed in versions 87.0.4280.66-1.el7, 87.0.4280.66-1.el8, 87.0.4280.66-1.fc32, 87.0.4280.66-1.fc33, 87.0.4280.88-1.el7, 87.0.4280.88-1.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in Adobe Flash Player
- Multiple vulnerabilities in Google Chrome
- Debian update for chromium
- Fedora 33 update for chromium
- Fedora 32 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 7 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 7 update for chromium