« Volver al listado

CVE-2019-13741

Estado: ModificadaAlta (8.8)—

Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-13741",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Chrome",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "79.0.3945.79",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-10T22:15:13.697",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html",
      "tags": [
        "Broken Link"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html",
      "tags": [
        "Broken Link"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4238",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://crbug.com/1011950",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://seclists.org/bugtraq/2020/Jan/27",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/202003-08",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://www.debian.org/security/2020/dsa-4606",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00032.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00036.html",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2019:4238",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://crbug.com/1011950",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2Z5M4FPUMDNX2LDPHJKN5ZV5GIS2AKNU/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N5CIQCVS6E3ULJCNU7YJXJPO2BLQZDTK/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://seclists.org/bugtraq/2020/Jan/27",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/202003-08",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2020/dsa-4606",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content."
    },
    {
      "lang": "es",
      "value": "Una comprobación insuficiente de una entrada no confiable en Blink en Google Chrome versiones anteriores a la versión  79.0.3945.79, permitió a un atacante local omitir la política del mismo origen por medio de un contenido de portapapeles especialmente  diseñado."
    }
  ],
  "lastModified": "2026-06-17T02:17:20.197",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3900404-81EC-4968-BD74-1630F385643D",
              "versionEndExcluding": "79.0.3945.79"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97A4B8DF-58DA-4AB6-A1F9-331B36409BA3"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80F0FA5D-8D3B-4C0E-81E2-87998286AF33"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "EB779E2B-B0A9-41F4-9000-4BAB848E7677"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "142A2E7B-9B0D-4335-8C92-FC9A6381DC8C"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "6194D474-EEEA-41FD-8FE8-090A9C10BDBF"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "1C493BF1-8890-4A3A-A207-FA5273259F61"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "F4C70C61-4DE2-49BE-81EA-9BCAC6F31C15"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "61F3999C-19F8-4723-8AC9-687FEFF27BD7"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "5F492BA1-72AD-4302-985E-EB2E465FC22B"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "BD58D619-D524-4690-85E4-ECE3B984D4B1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}