CVE-2018-6654: High severity Grammarly Grammarly Chrome vulnerability
The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr-ifr, because the exposure of these tokens is not restricted to any specific web site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Grammarly extension for Chrometo a version that resolves this vulnerability.Fixed in 2018-02-02
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6654?
CVE-2018-6654 has a high severity rating of 8.8 according to the CVSS 3.0 metrics.
How can I mitigate CVE-2018-6654?
To mitigate CVE-2018-6654, ensure that you update the Grammarly extension to the latest version released after February 2, 2018.
What vulnerabilities are associated with CVE-2018-6654?
CVE-2018-6654 allows remote attackers to discover authentication tokens, which can lead to unauthorized access.
Does CVE-2018-6654 affect all users of Grammarly?
Yes, CVE-2018-6654 affects all users of the Grammarly Chrome extension prior to the fixed version released on February 2, 2018.
What types of attacks are enabled by CVE-2018-6654?
CVE-2018-6654 enables attacks that can retrieve sensitive authentication tokens through an unprotected 'user' request.