CVE-2017-5075
—CVSS 3.1
4.3 medium
EPSS
1%p65
Published
()
Modified
Description
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
In the news0 stories
No ingested article mentions this CVE yet.