{"schema_version":"1.7.5","id":"CVE-2019-6251","published":"2019-01-14T08:29:00.223Z","modified":"2026-07-08T05:53:28.554480162Z","related":["SUSE-SU-2019:1137-1","SUSE-SU-2019:1155-1","openSUSE-SU-2019:1374-1","openSUSE-SU-2024:11506-1"],"details":"WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.","affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/epiphany","events":[{"introduced":"0"},{"last_affected":"312222a905de76adec9c77c986254f5837935e61"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:epiphany:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.31.4"}],"source":"CPE_RANGE"}}],"versions":["3.31.4","3.31.3","3.31.2","3.31.1","3.29.92","3.29.91","3.29.90","3.29.4","3.29.3","3.29.2","3.29.1","3.27.90","3.27.4","3.27.3","3.27.2","3.27.1","3.26.0","3.25.92","3.25.91","3.25.90","3.25.4","3.25.3","3.25.2","3.25.1","3.24.1","3.24.0","3.23.93","3.23.92","3.23.91.1","3.23.91","3.23.90","3.23.5","3.23.4","3.23.3","3.23.2.1","3.23.2","3.23.1.2","3.23.1.1","3.23.1","3.21.4","3.21.3","3.21.2","3.21.1","3.20.0","3.19.92","3.19.91","3.19.90","3.19.1","3.18.0","3.17.91","3.17.2","3.17.1","3.16.1","3.16.0","3.15.92","3.15.90","3.15.1","3.14.1","3.14.0","3.13.91","3.13.90","3.12.1","3.12.0","3.11.92","3.11.91","3.11.90","3.11.4","3.11.3","3.11.2","3.11.1","3.10.1","3.10.0","3.9.91","3.9.90","3.9.3","3.9.2","3.7.92","3.7.91","3.7.90","3.7.5","3.7.3","3.7.1","3.6.0","3.5.92","3.5.91.1","3.5.90","3.5.5","3.5.4","3.5.3","3.5.1","3.3.92","3.3.91","3.3.90","3.3.5","3.3.4.1","3.3.4","3.3.3","3.3.2","3.3.1","3.2.0","3.1.92","3.1.91.1","3.1.91","3.1.90","3.1.5","3.1.2","3.0.0","2.91.92","2.91.91.1","2.91.91","2.91.90","2.91.6","2.91.5","2.91.4.1","2.91.4","2.91.3","2.91.2","2.91.1.1","2.91.1","2.31.5","2.31.4","2.31.2","2.30.2","2.30.1","2.30","2.29.92","2.29.91","2.29.90","actual-2.29.6","2.29.6","2.29.5","2.29.3","2.29.1","2.27.92","2.27.91","2.27.90","2.27.5","2.27.4","RELEASE_2_23_91","RELEASE_2_21_92","RELEASE_2_21_90","RELEASE_2_21_5","RELEASE_2_21_4","RELEASE_2_19_90","RELEASE_2_19_6","XULRUNNER_BRANCHPOINT","RELEASE_2_19_5","RELEASE_2_19_2","RELEASE_2_18_0","GNOME_2_18_BRANCHPOINT","RELEASE_2_17_92","WEBKIT_BRANCHPOINT","RELEASE_2_17_91","RELEASE_2_17_90","RELEASE_2_17_5","RELEASE_2_17_4","RELEASE_2_17_3","RELEASE_2_17_2","GNOME_2_16_BRANCHPOINT","RELEASE_2_16_0","RELEASE_2_15_92","RELEASE_2_5_91","RELEASE_2_15_4","RELEASE_2_15_3","RELEASE_2_15_2","RELEASE_2_15_1","RELEASE_2_14_0","GNOME_2_14_BRANCHPOINT","Release1999","Release198","Release196","Release1951","Release195","Release194","Release1931","Release193","Release192","Release191","BEFORE_HARVES18","GNOME_2_12_BRANCHPOINT","Release176","Release175","PRE_GNOME_2_14_BRANCHPOINT","Release174","Release173","Release172","Release171","Release160","GNOME_2_10_ANCHOR","Release158","Release157","Release156","Release155","Release154","Release153","Release152","GTK_ENGINES_2_6_0","Release151","WEBCORE_BRANCHPOINT","help","gnome-2-8-branchpoint","pre-gnome-2-10-branchpoint","Release138","Release137","Release136","Release135","Release134","Release133","Release132","Release131","Release130","Release120","Release1112","Release1111","Release1110","Release119","Release117","Release115","Release113","Release112","Release111","Release110","Release092","Release091","Release090","Release083","Release082","Release081","Release073","Release072","Release070","INITIAL"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-6251.json"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSCDI3635E37GL4BNJDRDT2KEUBDLGSO/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LACVFU4MYYRPJ3IEA4UCN5KUEAGCCJ72/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNPI3R6QWDJBA5KNGA6QSMKYLY5RRHBZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO3DIA54X7FOUWFZW5YXC2MZ6KNHG6SW/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ/"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2019/04/11/1"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Apr/21"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201909-05"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3948-1/"},{"type":"REPORT","url":"https://bugs.webkit.org/show_bug.cgi?id=194208"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/epiphany/issues/532"},{"type":"FIX","url":"https://trac.webkit.org/changeset/243434"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"2.24.1"}],"source":"CPE_RANGE","vendor_product":"webkitgtk:webkitgtk"},{"cpes":["cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"2.24.1"}],"source":"CPE_RANGE","vendor_product":"wpewebkit:wpe_webkit"},{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"18.04"},{"last_affected":"18.04"},{"introduced":"18.10"},{"last_affected":"18.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"28"},{"last_affected":"28"},{"introduced":"29"},{"last_affected":"29"},{"introduced":"30"},{"last_affected":"30"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"cpes":["cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.0"},{"last_affected":"15.0"},{"introduced":"42.3"},{"last_affected":"42.3"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}