CVE-2021-38017

HIGH WAF: Low
CVSS 8.8 Published: 2021-12-23
CWE-863

Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
googlechromeup to 96.0.4664.45
fedoraprojectfedora34
debiandebian_linux10.0
debiandebian_linux11.0

References

Back to CVE Database