ZeroHour

CVE-2018-18358

CVSS 3.0
5.7 medium
EPSS
<1%p37
Published
()
Modified
Description

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

Vendors
googledebianredhat
Products
chrome, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-20
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.