CVE-2020-29623Incomplete Cleanup in Apple IOS AND Ipados

CWE-459Incomplete Cleanup7 documents7 sources
Severity
3.3LOWNVD
EPSS
0.0%
top 90.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateMay 24

Description

"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages9 packages

CVEListV5apple/tvosunspecified14.3
NVDapple/tvos< 14.3
CVEListV5apple/macosunspecified11.1
NVDapple/macos11.011.1.0
NVDapple/ipados< 14.3

Also affects: Fedora 32, 33

🔴Vulnerability Details

3
GHSA
GHSA-9723-8v87-36qm: "Clear History and Website Data" did not clear the history2022-05-24
CVEList
CVE-2020-29623: "Clear History and Website Data" did not clear the history2021-04-02
OSV
CVE-2020-29623: "Clear History and Website Data" did not clear the history2021-04-02

📋Vendor Advisories

3
Ubuntu
WebKitGTK vulnerabilities2021-03-29
Red Hat
webkitgtk: User may be unable to fully delete browsing history2021-03-22
Debian
CVE-2020-29623: webkit2gtk - "Clear History and Website Data" did not clear the history. The issue was addres...2020
CVE-2020-29623 — Incomplete Cleanup in Apple | cvebase