CVE-2009-2816
published 2009-11-13CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes…
PriorityP424medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.55%
72.4th percentile
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 4.0 | 4.0 |
| apple | safari | < 4.0.4 | 4.0.4 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 3.0.195.33 | 3.0.195.33 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wxv-94xf-vqv2: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4
ghsa_unreviewed·2022-05-02
CVE-2009-2816 [MEDIUM] CWE-352 GHSA-2wxv-94xf-vqv2: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
OSV
CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4
osv·2009-11-13·CVSS 6.8
CVE-2009-2816 [MEDIUM] CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
Red Hat
qt: MITM in the WebKit's Cross-Origin Resource Sharing (CORS) implementation
vendor_redhat·2009-11-11·CVSS 6.8
CVE-2009-2816 [MEDIUM] qt: MITM in the WebKit's Cross-Origin Resource Sharing (CORS) implementation
qt: MITM in the WebKit's Cross-Origin Resource Sharing (CORS) implementation
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/59940http://osvdb.org/59967http://secunia.com/advisories/37346http://secunia.com/advisories/37358http://secunia.com/advisories/37393http://secunia.com/advisories/37397http://secunia.com/advisories/43068http://support.apple.com/kb/HT3949http://support.apple.com/kb/HT4225http://www.securityfocus.com/bid/36997http://www.securitytracker.com/id?1023165http://www.vupen.com/english/advisories/2009/3217http://www.vupen.com/english/advisories/2009/3233http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=525789https://exchange.xforce.ibmcloud.com/vulnerabilities/54239https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6516https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00545.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00549.htmlhttp://lists.apple.com/archives/security-announce/2009/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/59940http://osvdb.org/59967http://secunia.com/advisories/37346http://secunia.com/advisories/37358http://secunia.com/advisories/37393http://secunia.com/advisories/37397http://secunia.com/advisories/43068http://support.apple.com/kb/HT3949http://support.apple.com/kb/HT4225http://www.securityfocus.com/bid/36997http://www.securitytracker.com/id?1023165http://www.vupen.com/english/advisories/2009/3217http://www.vupen.com/english/advisories/2009/3233http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=525789https://exchange.xforce.ibmcloud.com/vulnerabilities/54239https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6516https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00545.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00549.html
2009-11-13
Published