CVE-2010-0660

MEDIUM

Description

Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.

References

http://code.google.com/p/chromium/issues/detail?id=29920

http://googlechromereleases.blogspot.com/2010/01/stable-channel-update_25.html

http://securitytracker.com/id?1023506

http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14247

Details

Source: MITRE

Published: 2010-02-18

Updated: 2017-09-19

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM