Security Advisory

CVE-2017-5069

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-27 05:00:00
Last updated 2024-08-05 14:47:44
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page.