Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5hv-9846-hpc9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.

The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.

EPSS

Процентиль: 14%
0.00047
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 12 лет назад

The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.

EPSS

Процентиль: 14%
0.00047
Низкий

Дефекты

CWE-200