CVE-2019-8771 — UI Misrepresentation / Clickjacking in Apple Safari
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 43.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 24
Description
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages4 packages
🔴Vulnerability Details
4GHSA
▶
📋Vendor Advisories
5Debian▶
CVE-2019-8771: webkit2gtk - This issue was addressed with improved iframe sandbox enforcement. This issue is...↗2019