CVE-2018-20068: Input Validation
Published Jan 9, 2019
·Updated
Incorrect handling of 304 status codes in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.
Affected Software
1 affected component
Google Chrome<71.0.3578.80
Remediation
Patch Available
Event History
Jan 9, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-20068?
CVE-2018-20068 has a severity rating of medium.
2
How do I fix CVE-2018-20068?
To mitigate CVE-2018-20068, update Google Chrome to version 71.0.3578.80 or later.
3
What does CVE-2018-20068 affect?
CVE-2018-20068 affects Google Chrome versions prior to 71.0.3578.80.
4
What can an attacker do with CVE-2018-20068?
An attacker can exploit CVE-2018-20068 to confuse users regarding the origin of the current page by using a crafted HTML page.
5
When was CVE-2018-20068 reported?
CVE-2018-20068 was reported before the release of Google Chrome version 71.0.3578.80.