CVE-2013-6634
Published Dec 7, 2013
Last updated 11 years ago
Overview
- Description
- The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B166B1D-2593-4AC1-B6B7-136821A6C742", "versionEndIncluding": "31.0.1650.62" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ECE0CD4B-7AF0-408C-A0A4-5C1BF99DCC6F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E419AD3-959E-4CBE-AA82-6FF50ADA5F7D" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BB7361C-D835-4EA4-A02A-517A88235E48" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B8FBD4F-A625-4481-ACC3-11D1EC38E61F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54CE56C0-FEBB-4B88-B492-7F4834F1E7D5" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7C5BFB2-1662-40C8-91F3-BAADA15BBDB7" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1591A0BA-598A-4B52-990B-D897D0717659" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2399FF12-3C99-4822-9C7F-ACE21A75B07D" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A0F6EDE-7B69-4522-880B-5D384BA165B2" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F05FCCF-7EF3-4AE8-9699-C59716B64FEC" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2ABC4ED3-D2F4-49E4-917C-14CBD4B48217" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7DACE52-4FEE-46DB-8A3E-453927346324" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBB25316-F742-489F-982A-F2E93CC2A991" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7DCDDE4F-1AFF-47BB-AEED-1162557C3ED5" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7DC97D41-FC3F-4257-ADCF-A18CE16BD123" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08BB30B1-5D2B-4BF0-A9B2-E9DA58DB4421" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D94E9E7-694E-4D4D-87E3-C599BF0D34E0" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "95693DB4-F3A3-4E9B-81BC-9659DC28266F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "543A3EED-3B52-4F32-91CB-CE519502DAFC" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EA826854-B16A-4F3B-9B45-B20967C398CD" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.22:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D5EBF2E-E025-4F7F-8B59-E898526509CA" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57710E9D-5ACE-43B8-87E9-B62FE8602316" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2094C58D-F541-4622-8A85-0F29E8FA2C79" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "170A2964-5947-4DDB-8AE2-C919BEF38DF0" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "095EF1A2-A17B-4D1D-A314-770757DBC77F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "15659D3B-13DB-447D-B680-3CBA8A153B10" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "206DDB27-676F-4373-A0CC-762C9F593E77" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDE66FCD-C9F5-4341-983A-BED55E80C3CF" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E32F32F-BEFA-41E2-B77E-576662A36A45" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.32:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73CC0102-E20D-479C-AF93-1DBCD0052B10" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.33:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA262B88-A7F0-4F27-A002-7CFFF097D95E" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.34:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B6D23D07-42C3-49E6-B381-E4F8F7392ADA" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66941327-5BC4-4F22-920E-5A1E9A2A2234" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C01B6CFF-9602-4D81-BCB0-49F584B55AE7" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1DC5025C-3FEC-4C14-B785-5B3B8E093BC0" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.38:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FB6E22F-B320-449C-97A2-EB8BFB54B73E" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.39:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C13D619A-70FA-4C77-8603-6EEA8F6193D1" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.41:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "32059BF8-EF17-41C1-A0FC-39B41E775F3F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.42:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6636E503-0532-4E10-881E-C3E929CE5B9C" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.43:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C2259D6-6B9F-4625-9E69-CD157748ABBF" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.44:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C9F265B-5685-445B-9EEB-546849AD9272" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.45:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18F7A611-76FC-4AE4-8D5A-F7E75270FDA8" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.46:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2AF9C17-46A4-46F4-9D22-217EDE0AFAF2" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.47:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E2FC44E-D049-42B0-AD76-172C1ED06D41" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.48:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FCCB144-4569-4B53-9DE5-A5530135D6E2" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.49:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F37CEA3-76DF-4B01-BC5A-9DBC9C107C3D" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "699343EA-5C96-4ADB-AADE-3490197DFD8A" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.51:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CABE41D1-D7F1-417C-80D3-80C404BD9546" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.52:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C71B69CB-3D77-4931-9E3B-9225B7B63EC0" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.53:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1ED428E-3403-4363-A7B1-A68E65CF7A17" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.54:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C05E5233-03DE-425F-8328-106E52FDEF6F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.55:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61B4CB82-9609-4C90-8FC6-8BCC147B456F" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.57:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E1FDF34-2EB9-4FD7-AD77-026AE6D797AB" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.58:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B695203-6850-49BC-BAA8-A91E4350A713" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.59:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D1CB211-10B1-4133-89E2-E3F9B4BA2FA6" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.60:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1088A37-81E0-4BAA-917A-047DA78B4144" }, { "criteria": "cpe:2.3:a:google:chrome:31.0.1650.61:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB910D57-F102-4F8D-9A94-5A4DD30EF177" } ], "operator": "OR" } ] } ]