Upstream information

CVE-2024-0333 at MITRE

Description

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v3 Scores
  National Vulnerability Database
Base Score 5.3
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Impact None
Integrity Impact High
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1218719 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP5
  • chromedriver >= 120.0.6099.216-bp155.2.64.1
  • chromium >= 120.0.6099.216-bp155.2.64.1
Patchnames:
openSUSE-2024-20
openSUSE Leap 15.5
  • chromedriver >= 120.0.6099.216-bp155.2.64.1
  • chromium >= 120.0.6099.216-bp155.2.64.1
Patchnames:
openSUSE-2024-20
openSUSE Tumbleweed
  • chromedriver >= 120.0.6099.216-1.1
  • chromium >= 120.0.6099.216-1.1
  • libQt5Pdf5 >= 5.15.17-1.1
  • libQt5PdfWidgets5 >= 5.15.17-1.1
  • libqt5-qtpdf-devel >= 5.15.17-1.1
  • libqt5-qtpdf-examples >= 5.15.17-1.1
  • libqt5-qtpdf-imports >= 5.15.17-1.1
  • libqt5-qtpdf-private-headers-devel >= 5.15.17-1.1
  • libqt5-qtwebengine >= 5.15.17-1.1
  • libqt5-qtwebengine-devel >= 5.15.17-1.1
  • libqt5-qtwebengine-examples >= 5.15.17-1.1
  • libqt5-qtwebengine-private-headers-devel >= 5.15.17-1.1
  • ungoogled-chromium >= 120.0.6099.216-1.1
  • ungoogled-chromium-chromedriver >= 120.0.6099.216-1.1
Patchnames:
openSUSE-Tumbleweed-2024-13583
openSUSE-Tumbleweed-2024-13585
openSUSE-Tumbleweed-2024-14001


SUSE Timeline for this CVE

CVE page created: Thu Jan 11 10:45:10 2024
CVE page last modified: Sun Jun 16 03:01:09 2024