CVE-2019-6251
Last modified
CVE-2019-6251 is a vulnerability of currently unknown severity. WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. EPSS estimates a 4.13% chance of exploitation in the next 30 days.
Description
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Epiphany | <= 3.31.4 |
| Webkitgtk | Webkitgtk | < 2.24.1 |
| Wpewebkit | Wpe Webkit | < 2.24.1 |
| Fedoraproject | Fedora | 28 |
| Fedoraproject | Fedora | 29 |
| Fedoraproject | Fedora | 30 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.htmlThird Party Advisory
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/11/1Mailing List, Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=194208Issue Tracking, Vendor Advisory
- https://gitlab.gnome.org/GNOME/epiphany/issues/532Exploit, Patch, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/21Mailing List, Third Party Advisory
- https://trac.webkit.org/changeset/243434Patch, Vendor Advisory
- https://usn.ubuntu.com/3948-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.htmlThird Party Advisory
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/11/1Mailing List, Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=194208Issue Tracking, Vendor Advisory
- https://gitlab.gnome.org/GNOME/epiphany/issues/532Exploit, Patch, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/21Mailing List, Third Party Advisory
- https://trac.webkit.org/changeset/243434Patch, Vendor Advisory
- https://usn.ubuntu.com/3948-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6251?
How severe is CVE-2019-6251?
How do I fix CVE-2019-6251?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-6245An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as …8.8
- CVE-2019-6246An issue was discovered in SVG++ (aka svgpp) 1.2.3. After ca…
- CVE-2019-6247An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as …
- CVE-2019-6248PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Sc…
- CVE-2019-6249An issue was discovered in HuCart v5.7.4. There is a CSRF vu…
- CVE-2019-6250A pointer overflow, with code execution, was discovered in Z…
- CVE-2019-6256A Denial of Service issue was discovered in the LIVE555 Stre…
- CVE-2019-6257A Server Side Request Forgery (SSRF) vulnerability in elFind…7.7
- CVE-2019-6258D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and o…9.8
- CVE-2019-6259An issue was discovered in idreamsoft iCMS V7.0.13. There is…
- CVE-2019-6260The ASPEED ast2400 and ast2500 Baseband Management Controlle…
- CVE-2019-6261An issue was discovered in Joomla! before 3.9.2. Inadequate …
Are you affected by CVE-2019-6251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
