Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9359-5m76-c22m

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.

CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.

EPSS

Процентиль: 53%
0.003
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 11 лет назад

CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file.

EPSS

Процентиль: 53%
0.003
Низкий

Дефекты

CWE-200