cbcvebase.
CVE-2015-3752
published 2015-08-16

CVE-2015-3752: The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and…

PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.52%
81.6th percentile
The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly restrict cookie transmission for report requests, which allows remote attackers to obtain sensitive information via vectors involving (1) a cross-origin request or (2) a private-browsing request.

Affected

11 ranges
VendorProductVersion rangeFixed in
appleapple_tv
appleios
appleiphone_os< 8.4.18.4.1
applesafari>= 6.0 < 6.2.86.2.8
applesafari>= 7.0 < 7.1.87.1.8
applesafari>= 8.0 < 8.0.88.0.8
applesafari_8.0.8_safari_7.1.8_and_safari
canonicalubuntu_linux
canonicalubuntu_linux
webkitgtkwebkitgtk>= 0 < 2.4.10-0ubuntu0.14.04.12.4.10-0ubuntu0.14.04.1
webkitgtkwebkitgtk>= 0 < 2.4.10-0ubuntu12.4.10-0ubuntu1

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM