Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.
References
Link | Resource |
---|---|
http://code.google.com/p/chromium/issues/detail?id=30801 | Vendor Advisory |
http://code.google.com/p/chromium/issues/detail?id=33445 | Vendor Advisory |
http://googlechromereleases.blogspot.com/2010/03/stable-channel-update.html | Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14292 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2010-04-01 22:30
Updated : 2024-02-04 17:54
NVD link : CVE-2010-1230
Mitre link : CVE-2010-1230
CVE.ORG link : CVE-2010-1230
JSON object : View
Products Affected
- chrome
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor