CVE-2015-5841 — Injection in Apple Iphone OS
Severity
5.0MEDIUMNVD
EPSS
0.6%
top 29.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 17
Description
The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages6 packages
🔴Vulnerability Details
1GHSA▶
GHSA-7jc6-xq2h-q9cr: The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which↗2022-05-17