cbcvebase.
CVE-2019-8720
published 2023-03-06

CVE-2019-8720: A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved…

PriorityP182high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-13
Exploited in the wild
EPSS
1.54%
72.2th percentile
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianwebkit2gtk< webkit2gtk 2.26.0-1 (bookworm)webkit2gtk 2.26.0-1 (bookworm)
redhatcodeready_linux_builder
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_arm64_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_ibm_z_systems_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatcodeready_linux_builder_for_power_little_endian_eus
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_arm64_eus
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_power_big_endian
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition is processing maliciously crafted web content delivered to a WebKitGTK-based application (e.g., Epiphany); monitor for memory corruption signals (crashes, heap anomalies) in WebKitGTK processes when rendering remote content.
  • Vulnerable version boundary: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0. Detect unpatched installations by checking installed package versions against this threshold.
  • On Debian/Ubuntu systems, confirm fix by verifying webkit2gtk package is at version 2.26.0-1 or later; flag hosts running older versions as exposed.
  • After patching, restart all WebKitGTK+-dependent applications (e.g., Epiphany) to ensure the fix is active; running processes still using the old library remain exploitable.
  • ·Red Hat rates this as 'Moderate' severity because WebKitGTK is shipped only as a Gnome dependency, not as a standalone browser, reducing the practical attack surface on RHEL systems.
  • ·RHEL 6 (webkitgtk) is out of support scope and RHEL 7 (webkitgtk3) will not receive a fix for this CVE; detections on those platforms should account for permanently unpatched exposure.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.