CVE-2009-2198

CWE-2643 documents3 sources
Severity
4.3MEDIUM
EPSS
0.5%
top 34.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 4
Latest updateMay 2

Description

Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapple/garageband5.0.2+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8f2f-mjxj-j85g: Apple GarageBand before 52022-05-02
CVEList
CVE-2009-2198: Apple GarageBand before 52009-08-04
CVE-2009-2198 (MEDIUM CVSS 4.3) | Apple GarageBand before 5.1 reconfi | cvebase.io