CVE-2015-5236

Related Vulnerabilities: CVE-2015-5236  

A flaw was discovered that IcedTea-Web did not properly determine an applet's origin when performing same-origin checks. A malicious page could use this flaw to bypass the Same Origin Policy (SOP) and access data on unrelated sites using a spoofed value for the applet's codebase attribute.

Description

A flaw was discovered that IcedTea-Web did not properly determine an applet's origin when performing same-origin checks. A malicious page could use this flaw to bypass the Same Origin Policy (SOP) and access data on unrelated sites using a spoofed value for the applet's codebase attribute.

Additional Information

  • Bugzilla 1256403: CVE-2015-5236 icedtea-web: SOP checks based on codebase and not applet origin
  • CWE-345: Insufficient Verification of Data Authenticity
  • FAQ: Frequently asked questions about CVE-2015-5236