Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-30744

Опубликовано: 08 сент. 2021
Источник: debian
EPSS Низкий

Описание

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.32.3-1package
webkit2gtkignoredstretchpackage
wpewebkitfixed2.32.3-1package

Примечания

  • https://webkitgtk.org/security/WSA-2021-0004.html

EPSS

Процентиль: 68%
0.00573
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 4 года назад

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

CVSS3: 8.1
redhat
около 4 лет назад

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

CVSS3: 6.1
nvd
почти 4 года назад

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

CVSS3: 6.1
github
около 3 лет назад

Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.

CVSS3: 6.1
fstec
около 4 лет назад

Уязвимость элементов iframe модулей отображения веб-страниц WebKitGTK, WPE WebKit, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 68%
0.00573
Низкий