Bugzilla – Bug 1119836
VUL-0: CVE-2017-18352: chromium: Rendertron's error reporting allows reflected XSS
Last modified: 2019-02-27 18:14:13 UTC
CVE-2017-18352 Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18352 https://github.com/GoogleChrome/rendertron/pull/88 https://github.com/GoogleChrome/rendertron/commit/8d70628c96ae72eff6eebb451d26fc9ed6b58b0e https://bugs.chromium.org/p/chromium/issues/detail?id=759111
Does not seem to affect our chromium package. I can't find the code in the tarballs of current 72 release.
seems invalid