CVE-2020-6391: XSS
An insufficient validation of untrusted input flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1017871
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
Other sources
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 90.0.4430.212-1~deb10u1Fixed in 116.0.5845.180-1~deb11u1Fixed in 120.0.6099.129-1~deb11u1Fixed in 119.0.6045.199-1~deb12u1Fixed in 120.0.6099.129-1~deb12u1Fixed in 120.0.6099.129-1 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Upgrade
Upgrade
chromium/google chrometo a version that resolves this vulnerability.Fixed in 80.0.3987.87 - Compensating control
To mitigate while patching, prevent a local attacker from opening/visiting crafted HTML that could bypass content security policy (e.g., limit untrusted content exposure).
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-6391.
What is the severity level of CVE-2020-6391?
The severity level of CVE-2020-6391 is medium.
How can a local attacker exploit CVE-2020-6391?
A local attacker can exploit CVE-2020-6391 by bypassing content security policy via a crafted HTML page.
Which versions of Google Chrome are affected by CVE-2020-6391?
Google Chrome versions prior to 80.0.3987.87 are affected by CVE-2020-6391.
Where can I find more information about CVE-2020-6391?
You can find more information about CVE-2020-6391 at the following references: [1](https://code.google.com/p/chromium/issues/detail?id=1017871), [2](https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html), [3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1801839).