Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
References
Configurations
History
No history.
Information
Published : 2019-06-27 17:15
Updated : 2023-11-07 02:59
NVD link : CVE-2018-6148
Mitre link : CVE-2018-6148
CVE.ORG link : CVE-2018-6148
JSON object : View
Products Affected
- chrome
CWE
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')