CVE-2021-1769
published 2021-04-02CVE-2021-1769: A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.31%
22.9th percentile
A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_14.4_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 14.4 | 14.4 |
| apple | ipados | < 14.4 | 14.4 |
| apple | iphone_os | < 14.4 | 14.4 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.14 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.2 | 11.2 |
| apple | macos | >= unspecified < 11.2 | 11.2 |
| apple | macos | >= unspecified < 7.3 | 7.3 |
| apple | macos | >= unspecified < 14.4 | 14.4 |
| apple | macos_big_sur_11.2_security_update_2021-001_catalina_security_update_2021-001_mo | — | — |
| apple | tvos | < 14.4 | 14.4 |
| apple | watchos | < 7.3 | 7.3 |
| sap-cloud-sdk | core | >= 0 < 1.52.0 | 1.52.0 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-1769: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
vendor_apple·2021-02-01·CVSS 5.5
CVE-2021-1769 [MEDIUM] CVE-2021-1769: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
Apple Security Update: About the security content of macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
Product: macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
CVE: CVE-2021-1769
Component: Swift
Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: A logic issue was addressed with improved validation.
Apple
CVE-2021-1769: iOS 14.4 and iPadOS 14.4
vendor_apple·2021-01-26·CVSS 5.5
CVE-2021-1769 [MEDIUM] CVE-2021-1769: iOS 14.4 and iPadOS 14.4
Apple Security Update: About the security content of iOS 14.4 and iPadOS 14.4
Product: iOS 14.4 and iPadOS
Version: 14.4
CVE: CVE-2021-1769
Component: Swift
Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: A logic issue was addressed with improved validation.
GHSA
GHSA-gwp7-wwp2-44mq: A logic issue was addressed with improved validation
ghsa_unreviewed·2022-05-24
CVE-2021-1769 [MEDIUM] GHSA-gwp7-wwp2-44mq: A logic issue was addressed with improved validation
A logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
GHSA
Unauthorized access to data in @sap-cloud-sdk/core
ghsa·2021-11-10
CVE-2021-41251 [MEDIUM] CWE-200 Unauthorized access to data in @sap-cloud-sdk/core
Unauthorized access to data in @sap-cloud-sdk/core
### Impact
This affects applications on SAP Business Technology Platform that use the SAP Cloud SDK and enabled caching of destinations.
In some cases, when user information was missing, destinations were cached without user information, allowing other users to retrieve the same destination with its permissions.
By default, destination caching is disabled. If it is enabled the maximum lifetime is 5 minutes which limits the attack vector.
### Patches
The problem was fixed by #1769 and #1770. The security for caching has been increased. The changes are released in version 1.52.0.
### Workarounds
Disable destination caching (it is disabled by default).
### References
[destination cache API docs](https://sap.github.io/cloud-sdk/api/1.51.0/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT212146https://support.apple.com/en-us/HT212147https://support.apple.com/en-us/HT212148https://support.apple.com/en-us/HT212149https://support.apple.com/en-us/HT212146https://support.apple.com/en-us/HT212147https://support.apple.com/en-us/HT212148https://support.apple.com/en-us/HT212149
2021-04-02
Published