Tracker / CVE-2016-7153
CVE-2016-7153
Medium 5.3
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Affected products and versions
| apple | safari |
|---|---|
| chrome | |
| microsoft | edge |
| microsoft | internet_explorer |
| mozilla | firefox |
| opera | opera_browser |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.