4.3
CVSSv2

CVE-2018-11713

Published: 04/06/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

Vulnerable Product Search on Vulmon Subscribe to Product

webkitgtk webkitgtk\\+

gnome libsoup

Vendor Advisories

WebCore/platform/network/soup/SocketStreamHandleImplSoupcpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2200 or without libsoup 2620, unexpectedly failed to use system proxy settings for WebSocket connections As a result, users could be deanonymized by crafted web sites via a WebSocket connection ...