Overly permissive cross-domain whitelist in Google Chrome - CVE-2019-5832

 

Overly permissive cross-domain whitelist in Google Chrome - CVE-2019-5832

Published: August 17, 2023


Vulnerability identifier: #VU79649
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5832
CWE-ID: CWE-942
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass the CORS protection mechanism.

The vulnerability exists due to incorrect processing of CORS in XHR requests. A remote attacker can bypass implemented security restrictions.


Affected software

Google Chrome
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
chromium
chromium-browser (Red Hat package)
chromium-browser-debuginfo (Red Hat package)

How to mitigate CVE-2019-5832

Install updates from vendor's website.

Google Chrome - update to 75.0.3770.80
chromium - update to 75.0.3770.80-1
chromium-browser (Red Hat package) - update to 75.0.3770.80-1.el6_10
chromium-browser-debuginfo (Red Hat package) - update to 75.0.3770.80-1.el6_10

External References

Related Security Bulletins