CVE-2020-6484 describes an insufficient data validation vulnerability in ChromeDriver, affecting Google Chrome prior to version 83.0.4103.61, as well as various Linux distributions. A remote attacker could exploit this by crafting a request to bypass navigation restrictions. This medium-severity vulnerability (CVSS 6.5) requires user interaction and could lead to high integrity impact, though confidentiality and availability are not directly affected. While not listed on CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it garnered significant media coverage and community discussion, indicating awareness despite no active exploitation intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 83.0.4103.61CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.