Vulnerability Name: | CVE-2009-2816 (CCN-54239) |
Assigned: | 2009-11-11 |
Published: | 2009-11-11 |
Updated: | 2021-11-08 |
Summary: | The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-352
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2009-2816
Source: CCN Type: Google Chrome Releases Stable Update: Fix Google Chrome not Starting
Source: CCN Type: Google Chrome Releases Web site Stable Update: Fix Google Chrome not Starting
Source: APPLE Type: Mailing List, Patch, Vendor Advisory APPLE-SA-2009-11-11-1
Source: APPLE Type: Mailing List, Vendor Advisory APPLE-SA-2010-06-21-1
Source: SUSE Type: Third Party Advisory SUSE-SR:2011:002
Source: OSVDB Type: Broken Link 59940
Source: OSVDB Type: Broken Link 59967
Source: CCN Type: SA37346 Apple Safari Multiple Vulnerabilities
Source: SECUNIA Type: Third Party Advisory 37346
Source: CCN Type: SA37358 Google Chrome Cross-Origin Resource Sharing Security Bypass
Source: SECUNIA Type: Third Party Advisory 37358
Source: CCN Type: SA37393 Qt WebKit Multiple Vulnerabilities
Source: SECUNIA Type: Third Party Advisory 37393
Source: SECUNIA Type: Third Party Advisory 37397
Source: CCN Type: SA40257 Apple iOS Multiple Vulnerabilities
Source: SECUNIA Type: Third Party Advisory 43068
Source: CCN Type: SECTRACK ID: 1023165 Apple Safari WebKit Flaw Lets Remote Users Bypass Cross-Origin Resource Sharing Controls
Source: CCN Type: Apple KB HT3949 About the security content of Safari 4.0.4
Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT3949
Source: CCN Type: Apple Web site About the security content of iOS 4
Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT4225
Source: CCN Type: Webkit.org Web Site Changeset 47494
Source: CCN Type: OSVDB ID: 59940 Apple Safari WebKit Cross-Origin Resource Sharing Bypass
Source: CCN Type: OSVDB ID: 59967 Google Chrome WebKit OPTIONS Request Cross-Origin Resource Sharing Security Bypass
Source: BID Type: Third Party Advisory, VDB Entry 36997
Source: CCN Type: BID-36997 WebKit Preflight Request Same-Origin Policy Bypass Vulnerability
Source: SECTRACK Type: Third Party Advisory, VDB Entry 1023165
Source: VUPEN Type: Vendor Advisory ADV-2009-3217
Source: VUPEN Type: Vendor Advisory ADV-2009-3233
Source: VUPEN Type: Vendor Advisory ADV-2011-0212
Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=525789
Source: XF Type: Third Party Advisory, VDB Entry safari-crossorigin-csrf(54239)
Source: XF Type: UNKNOWN safari-crossorigin-csrf(54239)
Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:6516
Source: FEDORA Type: Third Party Advisory FEDORA-2009-11487
Source: FEDORA Type: Third Party Advisory FEDORA-2009-11491
Source: SUSE Type: SUSE-SR:2011:002 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:apple:safari:*:*:*:*:*:*:*:* (Version < 4.0.4)OR cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 3.0.195.33)OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 4.0) Configuration 2: cpe:/o:opensuse:opensuse:11.2:*:*:*:*:*:*:*OR cpe:/o:opensuse:opensuse:11.3:*:*:*:*:*:*:* Configuration 3: cpe:/o:fedoraproject:fedora:11:*:*:*:*:*:*:*OR cpe:/o:fedoraproject:fedora:12:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:apple:safari:3.0.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4_beta:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.0b:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.1b:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2b:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3b:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.0b:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.0:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.1:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0.2:-:ipodtouch:*:*:*:*:*OR cpe:/a:apple:safari:3.2.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:4.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:4.0.1:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_7:*:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:4.0.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:4.0.3:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.6.1:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.6.2:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.2:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.3:*:*:*:*:*:*:*OR cpe:/o:apple:iphone_os:2.1:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.0:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1.2:-:ipodtouch:*:*:*:*:*OR cpe:/o:apple:iphone_os:3.1:-:ipodtouch:*:*:*:*:*AND cpe:/o:microsoft:windows:xp:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_vista:*:*:*:*:*:*:*:*OR cpe:/a:trolltech:qt:4.2.3:*:*:*:*:*:*:*OR cpe:/a:google:chrome:3.0.195.24:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |