CVE-2018-4117: Cross orig in information leak in Blink
A cross origin information leak flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=791324
External References:
https://chromereleases.googleblog.com/2018/07/stable-channel-update-for-desktop.html
Other sources
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
— Launchpad
WebKit. A cross-origin issue existed with the fetch API. This was addressed through improved input validation.
WebKit. A cross-origin issue existed with the fetch API. This was addressed with improved input validation.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-4155
- CVE-2018-4158
- CVE-2018-4142
- CVE-2018-4167
- CVE-2018-4150
- CVE-2018-4104
- CVE-2018-4143
- CVE-2018-4185
- CVE-2017-15412
- CVE-2018-4390
- CVE-2018-4391
- CVE-2018-4166
- CVE-2018-4157
- CVE-2018-4144
- CVE-2018-4115
- CVE-2018-4113
- CVE-2018-4146
- CVE-2018-4114
- CVE-2018-4121
- CVE-2018-4122
- CVE-2018-4125
- CVE-2018-4129
- CVE-2018-4161
- CVE-2018-4162
- CVE-2018-4163
- CVE-2018-4117
- CVE-2018-4207
- CVE-2018-4208
- CVE-2018-4209
- CVE-2018-4210
- CVE-2018-4212
- CVE-2018-4213
- CVE-2018-4145
- CVE-2018-4101
- CVE-2018-4118
- CVE-2018-4119
- CVE-2018-4120
- CVE-2018-4127
- CVE-2018-4128
- CVE-2018-4130
- CVE-2018-4165
- CVE-2018-6153
- CVE-2018-6154
- CVE-2018-6155
- CVE-2018-6156
- CVE-2018-6157
- CVE-2018-6158
- CVE-2018-6159
- CVE-2018-6160
- CVE-2018-6161
- CVE-2018-6162
- CVE-2018-6163
- CVE-2018-6164
- CVE-2018-6165
- CVE-2018-6166
- CVE-2018-6167
- CVE-2018-6168
- CVE-2018-6169
- CVE-2018-6170
- CVE-2018-6171
- CVE-2018-6172
- CVE-2018-6173
- CVE-2018-6174
- CVE-2018-6175
- CVE-2018-6176
- CVE-2018-6177
- CVE-2018-6178
- CVE-2018-6179
- CVE-2018-6044
- CVE-2018-17460
- CVE-2018-17461
- CVE-2018-6150
- CVE-2018-6151
- CVE-2018-6152
- CVE-2018-4102
- CVE-2018-4116
- CVE-2018-4186
- CVE-2018-4137
- CVE-2018-4133
- CVE-2018-4177
- CVE-2018-4123
- CVE-2018-4168
- CVE-2018-4172
- CVE-2018-4151
- CVE-2018-4187
- CVE-2018-4174
- CVE-2018-4156
- CVE-2018-4134
- CVE-2018-4149
- CVE-2018-4173
- CVE-2018-4154
- CVE-2018-4140
- CVE-2018-4148
- CVE-2018-4110
- CVE-2018-4131
Frequently Asked Questions
What is vulnerability CVE-2018-4117?
Vulnerability CVE-2018-4117 is a cross-origin issue in the fetch API component of WebKit.
Which Apple products are affected by CVE-2018-4117?
iOS before 11.3, Safari before 11.1, iCloud before 7.4 on Windows, iTunes before 12.7.4 on Windows, and watchOS before 4.3 are affected.
What is the severity of CVE-2018-4117?
CVE-2018-4117 has a severity rating of 6.5 (medium).
How can I fix CVE-2018-4117?
To fix CVE-2018-4117, it is recommended to update to the latest available version of the affected software.
Where can I find more information about CVE-2018-4117?
You can find more information about CVE-2018-4117 on the following websites: securityfocus.com, securitytracker.com, and access.redhat.com.