Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8498.
2017-06-15T01:29:03.693
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | edge | * | Yes |
Operating System | microsoft | windows_10 | 1607 | No |
Operating System | microsoft | windows_10 | 1703 | No |
Operating System | microsoft | windows_server_2016 | * | No |