Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-24150

Опубликовано: 27 янв. 2025
Источник: redhat
CVSS3: 8.8

Описание

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.

A flaw was found in WebKitGTK. Copying a URL from Web Inspector may lead to command injection due to improper file handling.

Отчет

To exploit this flaw, an attacker needs to trick a user into performing unlikely actions, such as enabling and opening the web inspector in an application and loading malicious web content into it. For this reason, this flaw has been rated with a Moderate severity.

Меры по смягчению последствий

Do not process or load untrusted web content with WebKitGTK.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7webkitgtk3Out of support scope
Red Hat Enterprise Linux 9webkit2gtk3Affected
Red Hat Enterprise Linux 7 Extended Lifecycle Supportwebkitgtk4FixedRHSA-2025:1036407.07.2025
Red Hat Enterprise Linux 8webkit2gtk3FixedRHSA-2025:203403.03.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2344622webkitgtk: Copying a URL from Web Inspector may lead to command injection

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 месяцев назад

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.

CVSS3: 8.8
nvd
6 месяцев назад

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.

CVSS3: 8.8
debian
6 месяцев назад

A privacy issue was addressed with improved handling of files. This is ...

CVSS3: 8.8
github
6 месяцев назад

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.

CVSS3: 8.8
fstec
6 месяцев назад

Уязвимость инструмента проверки веб-страниц Web Inspector операционных систем iOS, iPadOS, macOS и браузера Safari, позволяющая нарушителю выполнить произвольные команды

8.8 High

CVSS3