The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published: 2015-01-22T22:00:00

Updated: 2024-08-06T13:03:27.658Z

Reserved: 2014-10-06T00:00:00

Link: CVE-2014-7948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-01-22T22:59:27.770

Modified: 2023-11-07T02:22:05.237

Link: CVE-2014-7948

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-01-21T00:00:00Z

Links: CVE-2014-7948 - Bugzilla