CVE-2018-6082: Infoleak
Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
Other sources
The following flaw was identified in the Chromium browser: circumvention of port blocking.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=767354
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6082?
CVE-2018-6082 is considered a moderate severity vulnerability.
How do I fix CVE-2018-6082?
To fix CVE-2018-6082, upgrade to Chromium version 65.0.3325.146 or later.
What does CVE-2018-6082 affect?
CVE-2018-6082 affects Google Chrome versions prior to 65.0.3325.146 and certain versions of the Chromium browser.
Can CVE-2018-6082 lead to internal service enumeration?
Yes, CVE-2018-6082 could allow an attacker to potentially enumerate internal host services.
Which versions of Chromium are vulnerable to CVE-2018-6082?
Chromium versions prior to 65.0.3325.146 are vulnerable to CVE-2018-6082.