First published: Mon Jun 15 2009(Updated: )
Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera | =8.52 | |
Opera | =7.50-beta_1 | |
Opera | =5.10 | |
Opera | =5..10 | |
Opera | =7.20 | |
Opera | =7.52 | |
Opera | =9.02 | |
Opera | =7.20-beta7 | |
Opera | =5.02 | |
Opera | =8.53 | |
Opera | =5.2 | |
Opera | =5.4 | |
Opera | =6.1 | |
Opera | =6.12 | |
Opera | =7.30 | |
Opera | =5.12 | |
Opera | =7.22 | |
Opera | =5.0-beta_2 | |
Opera | =7.50 | |
Opera | =5.0-beta_3 | |
Opera | =5.0-beta_7 | |
Opera | =7.0 | |
Opera | =8.0 | |
Opera | =8.01 | |
Opera | =8.54 | |
Opera | =6.03 | |
Opera | =8.51 | |
Opera | =7.55 | |
Opera | =6.06 | |
Opera | =7.0-beta_1v2 | |
Opera | =7.03 | |
Opera | =7.0-beta_1 | |
Opera | =9.01 | |
Opera | =5.0 | |
Opera | =6.0-beta_3 | |
Opera | =6.11 | |
Opera | =6.02 | |
Opera | =6-beta_1 | |
Opera | =9.23 | |
Opera | =6.0 | |
Opera | =6.01 | |
Opera | =7-beta_1 | |
Opera | =9.0-beta_1 | |
Opera | =7.10 | |
Opera | =5.0-beta_4 | |
Opera | =9.20 | |
Opera | =5.6 | |
Opera | =6.0-beta_1 | |
Opera | =5.5 | |
Opera | =5.8 | |
Opera | =7.54-update_1 | |
Opera | =5.3 | |
Opera | =8.0-beta_2 | |
Opera | =7.23 | |
Opera | =5.1 | |
Opera | =5.11 | |
Opera | =5.0-beta_6 | |
Opera | =6.04 | |
Opera | =6.05 | |
Opera | =6.0-beta_2 | |
Opera | =5.7 | |
Opera | =7.01 | |
Opera | =7.51 | |
Opera | =8.0-beta_1 | |
Opera | =9.10 | |
Opera | =7.54 | |
Opera | =7.11 | |
Opera | =5.9 | |
Opera | =7.02 | |
Opera | =5.0-beta_5 | |
Opera | =7.21 | |
Opera | =9.21 | |
Opera | =8.02 | |
Opera | =7.0-beta_2 | |
Opera | =5.0-beta_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2068 is rated as a medium severity vulnerability.
To fix CVE-2009-2068, ensure that all content loaded in HTTPS pages is served over HTTPS and update your web application to prevent mixed content loading.
CVE-2009-2068 affects multiple versions of the Opera browser.
CVE-2009-2068 allows man-in-the-middle attackers to inject arbitrary web scripts into HTTPS sites.
CVE-2009-2068 compromises user security by enabling attackers to execute scripts within the context of secure pages, potentially exposing sensitive information.