cvelist/2020/15xxx/CVE-2020-15959.json
2021-01-26 18:06:43 +00:00

108 lines
3.9 KiB
JSON

{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2020-15959",
"ASSIGNER": "chrome-cve-admin@google.com",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Google",
"product": {
"product_data": [
{
"product_name": "Chrome",
"version": {
"version_data": [
{
"version_value": "85.0.4183.102",
"version_affected": "<"
}
]
}
}
]
}
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Insufficient policy enforcement"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://crbug.com/1122684",
"refsource": "MISC",
"name": "https://crbug.com/1122684"
},
{
"url": "https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html",
"refsource": "MISC",
"name": "https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1499",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00072.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1510",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00078.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1514",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00081.html"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-2d994b986d",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GNIYFJST4TFJYFZ27VODBOINCLBGULTD/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-aea86f913e",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FN7HZIGAOCZKBT4LV363BCPRA5FLY25I/"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1713",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00049.html"
},
{
"refsource": "DEBIAN",
"name": "DSA-4824",
"url": "https://www.debian.org/security/2021/dsa-4824"
},
{
"refsource": "GENTOO",
"name": "GLSA-202101-30",
"url": "https://security.gentoo.org/glsa/202101-30"
}
]
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering."
}
]
}
}