CVE-2019-8674
published 2019-12-18CVE-2019-8674: A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to…
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < iOS 13 | iOS 13 |
| apple | iphone_os | < 13.0 | 13.0 |
| apple | safari | < 13 | 13 |
| apple | safari | — | — |
| apple | safari | >= unspecified < Safari 13 | Safari 13 |
| debian | webkit2gtk | < webkit2gtk 2.24.4-1 (bookworm) | webkit2gtk 2.24.4-1 (bookworm) |
| webkitgtk | webkitgtk | < 2.26.4 | 2.26.4 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
GHSA
GHSA-42p8-xc23-48xv: A logic issue was addressed with improved state management
ghsa_unreviewed·2022-05-24
CVE-2019-8674 [MEDIUM] CWE-79 GHSA-42p8-xc23-48xv: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
OSV
CVE-2019-8674: A logic issue was addressed with improved state management
osv·2019-12-18·CVSS 6.1
CVE-2019-8674 [MEDIUM] CVE-2019-8674: A logic issue was addressed with improved state management
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Red Hat
webkitgtk: Incorrect state management leading to universal cross-site scripting
vendor_redhat·2019-10-29·CVSS 6.1
CVE-2019-8674 [MEDIUM] webkitgtk: Incorrect state management leading to universal cross-site scripting
webkitgtk: Incorrect state management leading to universal cross-site scripting
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Apple
CVE-2019-8674: iOS 13
vendor_apple·2019-09-19·CVSS 6.1
CVE-2019-8674 [MEDIUM] CVE-2019-8674: iOS 13
Apple Security Update: About the security content of iOS 13
Product: iOS
Version: 13
CVE: CVE-2019-8674
Component: WebKit Page Loading
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue was addressed with improved state management.
Apple
CVE-2019-8674: Safari 13
vendor_apple·2019-09-19·CVSS 6.1
CVE-2019-8674 [MEDIUM] CVE-2019-8674: Safari 13
Apple Security Update: About the security content of Safari 13
Product: Safari
Version: 13
CVE: CVE-2019-8674
Component: WebKit Page Loading
Impact: Processing maliciously crafted web content may lead to universal cross site scripting
Description: A logic issue was addressed with improved state management.
Debian
CVE-2019-8674: webkit2gtk - A logic issue was addressed with improved state management. This issue is fixed ...
vendor_debian·2019·CVSS 6.1
CVE-2019-8674 [MEDIUM] CVE-2019-8674: webkit2gtk - A logic issue was addressed with improved state management. This issue is fixed ...
A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.
Scope: local
bookworm: resolved (fixed in 2.24.4-1)
bullseye: resolved (fixed in 2.24.4-1)
forky: resolved (fixed in 2.24.4-1)
sid: resolved (fixed in 2.24.4-1)
trixie: resolved (fixed in 2.24.4-1)
No detection rules found.
No public exploits indexed.
2019-12-18
Published