2020-01-08 15:01:01 +00:00
{
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"data_version" : "4.0" ,
"CVE_data_meta" : {
"ID" : "CVE-2020-6506" ,
2020-07-22 17:01:35 +00:00
"ASSIGNER" : "chrome-cve-admin@google.com" ,
"STATE" : "PUBLIC"
2020-07-22 09:10:53 -07:00
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Google" ,
"product" : {
"product_data" : [
{
"product_name" : "Chrome" ,
"version" : {
"version_data" : [
{
"version_value" : "83.0.4103.106" ,
"version_affected" : "<"
}
]
}
}
]
}
}
]
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "Insufficient policy enforcement"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
2020-07-22 17:01:35 +00:00
"url" : "https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html" ,
"refsource" : "MISC" ,
"name" : "https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html"
2020-07-22 09:10:53 -07:00
} ,
{
2020-07-22 17:01:35 +00:00
"url" : "https://crbug.com/1083819" ,
"refsource" : "MISC" ,
"name" : "https://crbug.com/1083819"
2020-07-27 02:01:22 +00:00
} ,
{
"refsource" : "GENTOO" ,
"name" : "GLSA-202007-08" ,
"url" : "https://security.gentoo.org/glsa/202007-08"
2020-09-30 18:02:14 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-issues] 20200929 [GitHub] [cordova-docs] purplecabbage opened a new pull request #1123: Added Security Advisory CVE-2020-6506" ,
"url" : "https://lists.apache.org/thread.html/r1eadf38b38ee20405811958c8a01f78d6b28e058c84c9fa6c1a8663d@%3Cissues.cordova.apache.org%3E"
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-issues] 20200929 [GitHub] [cordova-docs] purplecabbage merged pull request #1123: Added Security Advisory CVE-2020-6506" ,
"url" : "https://lists.apache.org/thread.html/r2769c33da7f7ece7e4e31837c1e1839d6657c7c13bb8d228670b8da0@%3Cissues.cordova.apache.org%3E"
2020-10-01 18:01:53 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-issues] 20201001 [GitHub] [cordova-docs] dpogue commented on issue #1022: Document warnings on using remote source for <content>" ,
"url" : "https://lists.apache.org/thread.html/r1ab80f8591d5c2147898076e3945dad1c897513630aabec556883275@%3Cissues.cordova.apache.org%3E"
2020-10-07 18:01:44 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-issues] 20201007 [GitHub] [cordova-plugin-inappbrowser] carlpoole opened a new pull request #792: fix(android): Add mitigation strategy for CVE-2020-6506" ,
"url" : "https://lists.apache.org/thread.html/rc0ebe639927fa09e222aa56bf5ad6e700218f334ecc6ba9da4397728@%3Cissues.cordova.apache.org%3E"
2020-11-16 19:01:35 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-issues] 20201116 [GitHub] [cordova-plugin-inappbrowser] NiklasMerz commented on pull request #792: fix(android): Add mitigation strategy for CVE-2020-6506" ,
"url" : "https://lists.apache.org/thread.html/ra58733fbb88d5c513b3f14a14850083d506b9129103e0ab433c3f680@%3Cissues.cordova.apache.org%3E"
2020-11-17 18:01:37 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-issues] 20201117 [GitHub] [cordova-plugin-inappbrowser] NiklasMerz merged pull request #792: fix(android): Add mitigation strategy for CVE-2020-6506" ,
"url" : "https://lists.apache.org/thread.html/rc81e12fc9287f8743d59099b1af40f968f1cfec9eac98a63c2c62c69@%3Cissues.cordova.apache.org%3E"
2021-01-26 18:07:03 +00:00
} ,
{
"refsource" : "MLIST" ,
"name" : "[cordova-commits] 20201117 [cordova-plugin-inappbrowser] branch master updated: fix(android): Add mitigation strategy for CVE-2020-6506 (#792)" ,
"url" : "https://lists.apache.org/thread.html/rf082834ad237f78a63671aec0cef8874f9232b7614529cc3d3e304c5@%3Ccommits.cordova.apache.org%3E"
} ,
{
"refsource" : "GENTOO" ,
"name" : "GLSA-202101-30" ,
"url" : "https://security.gentoo.org/glsa/202101-30"
2020-07-22 09:10:53 -07:00
}
]
2020-01-08 15:01:01 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2020-07-22 09:10:53 -07:00
"value" : "Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page."
2020-01-08 15:01:01 +00:00
}
]
}
}