« Volver al listado

CVE-2020-27969

Estado: ModificadaAlta (7.3)—

Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-27969",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "browser-security@yandex-team.ru",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Yandex Browser for Android",
          "versions": [
            {
              "status": "affected",
              "version": "All versions prior to version 20.8.4."
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-09-13T12:15:07.260",
  "references": [
    {
      "url": "https://yandex.com/bugbounty/i/hall-of-fame-browser/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "browser-security@yandex-team.ru"
    },
    {
      "url": "https://yandex.com/bugbounty/i/hall-of-fame-browser/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing"
    },
    {
      "lang": "es",
      "value": "Yandex Browser para Android versión 20.8.4, permite a atacantes remotos llevar a cabo una omisión del SOP y una suplantación de la barra de direcciones"
    }
  ],
  "lastModified": "2026-06-17T03:09:56.637",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8749B748-DF80-4ACD-8164-ABD646DFCAD1",
              "versionEndExcluding": "20.8.4"
            },
            {
              "criteria": "cpe:2.3:a:yandex:yandex_browser:20.8.4:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC97D657-2A71-43BC-9861-1AC5BE294817"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "browser-security@yandex-team.ru"
}