The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2811-1 chromium-browser security update
EUVD EUVD EUVD-2013-6436 The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T17:46:22.394Z

Reserved: 2013-11-05T00:00:00

Link: CVE-2013-6634

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-12-07T00:55:03.820

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-6634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses