CVE-2023-2465: Inappropriate implementation in CORS
Chromium: CVE-2023-2465 Inappropriate implementation in CORS
Other sources
Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-2465?
CVE-2023-2465 is a vulnerability in the Chromium browser that allows a remote attacker to leak cross-origin data through a crafted HTML page.
How severe is CVE-2023-2465?
CVE-2023-2465 is considered a medium severity vulnerability.
Which software is affected by CVE-2023-2465?
Chromium versions prior to 113.0.5672.63, Microsoft Edge versions up to 113.0.1774.35, and Microsoft Edge (Chromium-based) are affected by CVE-2023-2465.
How can I fix CVE-2023-2465?
To fix CVE-2023-2465, update your Chromium browser to at least version 113.0.5672.63 or upgrade to a secure version of Microsoft Edge.
Where can I find more information about CVE-2023-2465?
You can find more information about CVE-2023-2465 in the references provided: https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop.html, https://crbug.com/1399862, https://www.debian.org/security/2023/dsa-5398