Vulnerability Name: | CVE-2018-4377 (CCN-152284) | ||||||||||||
Assigned: | 2018-10-30 | ||||||||||||
Published: | 2018-10-30 | ||||||||||||
Updated: | 2019-04-05 | ||||||||||||
Summary: | A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12.1, watchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8. | ||||||||||||
CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-4377 Source: XF Type: UNKNOWN apple-safari-cve20184377-uxss(152284) Source: CCN Type: Apple security document HT209196 About the security content of Safari 12.0.1 Source: CCN Type: Apple security document HT209197 About the security content of iTunes 12.9.1 for Windows Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT209192 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT209195 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT209196 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT209197 Source: MISC Type: Vendor Advisory https://support.apple.com/kb/HT209198 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
BACK |