CVE-2009-2068: Medium severity Opera Opera vulnerability
Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2068?
CVE-2009-2068 is rated as a medium severity vulnerability.
How do I fix CVE-2009-2068?
To fix CVE-2009-2068, ensure that all content loaded in HTTPS pages is served over HTTPS and update your web application to prevent mixed content loading.
Which applications are affected by CVE-2009-2068?
CVE-2009-2068 affects multiple versions of the Opera browser.
What types of attacks are possible with CVE-2009-2068?
CVE-2009-2068 allows man-in-the-middle attackers to inject arbitrary web scripts into HTTPS sites.
How does CVE-2009-2068 impact user security?
CVE-2009-2068 compromises user security by enabling attackers to execute scripts within the context of secure pages, potentially exposing sensitive information.