Overly permissive cross-domain whitelist in Adobe Flash Player - CVE-2019-8075

 

Overly permissive cross-domain whitelist in Adobe Flash Player - CVE-2019-8075

Published: September 27, 2019 / Updated: November 17, 2020


Vulnerability identifier: #VU48483
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8075
CWE-ID: CWE-942
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the CORS protection mechanism.

The vulnerability exists due to incorrect processing of the "Origin" HTTP header that is supplied within HTTP request in Adobe Flash player. A remote attacker can bypass implemented same origin policy restrictions and gain access to sensitive information from another domain.


Affected software

Adobe Flash Player
Fedora
chromium (Debian package)
chromium
Google Chrome

How to mitigate CVE-2019-8075

Install updates from vendor's website.

Adobe Flash Player - update to 32.0.0.207
chromium (Debian package) - update to 87.0.4280.88-0.4~deb10u1
Google Chrome - update to 87.0.4280.66
chromium - addressed in versions 87.0.4280.66-1.el7, 87.0.4280.66-1.el8, 87.0.4280.66-1.fc32, 87.0.4280.66-1.fc33, 87.0.4280.88-1.el7, 87.0.4280.88-1.el8

External References

Related Security Bulletins