Уязвимость нарушения уникального происхождения безопасности DOM объекта в продуктах Apple
Описание
Уязвимость логической ошибки связана с некорректной проверкой, которая может привести к тому, что объект DOM не имеет уникального происхождения безопасности.
Затронутые версии ПО
- iCloud для Windows 7.17
- iTunes 12.10.4 для Windows
- iCloud для Windows 10.9.2
- tvOS 13.3.1
- Safari 13.0.5
- iOS 13.3.1
- iPadOS 13.3.1
Тип уязвимости
Нарушение уникальности происхождения безопасности для DOM объектов
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
Связанные уязвимости
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
A logic issue was addressed with improved validation. This issue is fi ...
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
EPSS
7.8 High
CVSS3
7.2 High
CVSS2