CVE-2019-5783: Insufficient validation of untrusted input in DevTools
Published Oct 13, 2018
·Updated
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
Credit
Shintaro Kobori
Affected Software
4 affected componentsFixes available
debian/chromium
90.0.4430.212-1~deb10u1116.0.5845.180-1~deb11u1118.0.5993.70-1~deb11u1116.0.5845.180-1~deb12u1118.0.5993.70-1~deb12u1118.0.5993.70-1
Google Chrome<72.0.3626.81
72.0.3626.81
Google Chrome<72.0.3626.81
Debian Debian Linux=9.0
Event History
Oct 13, 2018
CVE Published
12:00 AM
Feb 19, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-5754
- CVE-2019-5782
- CVE-2019-5755
- CVE-2019-5756
- CVE-2019-5757
- CVE-2019-5758
- CVE-2019-5759
- CVE-2019-5760
- CVE-2019-5761
- CVE-2019-5762
- CVE-2019-5763
- CVE-2019-5764
- CVE-2019-13768
- CVE-2019-5765
- CVE-2019-5785
- CVE-2019-5766
- CVE-2019-5767
- CVE-2019-5768
- CVE-2019-5769
- CVE-2019-5770
- CVE-2019-5771
- CVE-2019-5772
- CVE-2019-5773
- CVE-2019-5774
- CVE-2019-5775
- CVE-2019-5776
- CVE-2019-5777
- CVE-2018-20073
- CVE-2019-5778
- CVE-2019-5779
- CVE-2019-5780
- CVE-2019-5781
- CVE-2019-13684
Frequently Asked Questions
1
What is the severity of CVE-2019-5783?
CVE-2019-5783 is classified as a high-severity vulnerability due to its potential for exploitation allowing Dangling Markup Injection attacks.
2
How do I fix CVE-2019-5783?
To fix CVE-2019-5783, update your Google Chrome or Chromium browser to version 72.0.3626.81 or later.
3
What causes CVE-2019-5783?
CVE-2019-5783 is caused by missing URI encoding of untrusted input in the DevTools of Google Chrome.
4
Which versions of Google Chrome are affected by CVE-2019-5783?
CVE-2019-5783 affects Google Chrome versions prior to 72.0.3626.81.
5
Is any specific operating system affected by CVE-2019-5783?
CVE-2019-5783 affects Google Chrome on multiple operating systems, including Debian Linux.