CVE-2010-0660: Infoleak
Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0660?
CVE-2010-0660 is classified as a moderate severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2010-0660?
To fix CVE-2010-0660, users should update Google Chrome to version 4.0.249.78 or later.
What types of systems are affected by CVE-2010-0660?
CVE-2010-0660 affects various versions of Google Chrome prior to 4.0.249.78, including 0.2.x, 1.x, 2.x, and 3.x series.
What information could be exposed by CVE-2010-0660?
CVE-2010-0660 may allow remote HTTP servers to obtain potentially sensitive information from the Referer header of a request.
Is there a workaround for CVE-2010-0660?
There is no specific workaround for CVE-2010-0660; the recommended action is to update to a secure version of Google Chrome.