CVE-2017-5120 describes an inappropriate use of www mismatch redirects in Google Chrome versions prior to 61.0.3163.79 (Mac, Windows, Linux) and 61.0.3163.81 (Android), affecting products from Apple, Debian, Google, Linux, Microsoft, and Red Hat. This vulnerability allowed a remote attacker, via a crafted HTML page, to potentially downgrade HTTPS requests to HTTP, leading to cleartext transmission despite the user entering an HTTPS URL. With a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and requires user interaction (UI:R) but could result in a high impact on integrity (I:H), as it bypasses the intended secure connection. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog, indicating low current exploitation risk and limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 61.0.3163.79CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
< 61.0.3163.81CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.