cbcvebase.
CVE-2021-30823
published 2021-10-28

CVE-2021-30823: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.

Affected

20 ranges
VendorProductVersion rangeFixed in
appleicloud_for_windows
appleios_14.8_and_ipados
appleios_and_ipados>= unspecified < 14.814.8
appleipados< 14.814.8
appleiphone_os< 14.814.8
appleitunes_12.12_for_windows
applemacos< 12.0.112.0.1
applemacos>= unspecified < 12.012.0
applemacos_monterey
applesafari< 15.0.015.0.0
applesafari
applesafari>= unspecified < 1515
appletvos< 15.015.0
appletvos
appletvos>= unspecified < 1515
applewatchos< 8.08.0
applewatchos>= unspecified < 88
applewatchos_8
debianwebkit2gtk< webkit2gtk 2.34.1-1 (bookworm)webkit2gtk 2.34.1-1 (bookworm)
debianwpewebkit< webkit2gtk 2.34.1-1 (bookworm)webkit2gtk 2.34.1-1 (bookworm)

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM