Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Chrome ‘OneClickSigninHelper::ShowInfoBarIfPossible’函数会话固定漏洞
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。 Google Chrome 31.0.1650.63之前的版本中的browser/ui/sync/one_click_signin_helper.cc文件中的‘OneClickSigninHelper::ShowInfoBarIfPossible’函数中存在安全漏洞,该漏洞源于当进行边界验证时使用错误的URL。远程攻击者可通过在HTTP返回状态为302后,触发错误的同步利用该漏洞进行会话固定攻击,劫持Web会话。
CVSS Information
N/A
Vulnerability Type
N/A