CVE-2022-22592

CWE-1021Clickjacking12 documents8 sources
Severity
6.5MEDIUM
EPSS
0.2%
top 60.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMar 19

Description

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages12 packages

CVEListV5apple/tvosunspecified15.3
NVDapple/tvos< 15.3
CVEListV5apple/macosunspecified12.2
NVDapple/macos12.0.012.2
NVDapple/ipados< 15.3

🔴Vulnerability Details

3
GHSA
GHSA-4r4q-3gg9-w59h: A logic issue was addressed with improved state management2022-03-19
OSV
CVE-2022-22592: A logic issue was addressed with improved state management2022-03-18
CVEList
CVE-2022-22592: A logic issue was addressed with improved state management2022-03-18

📋Vendor Advisories

8
Ubuntu
WebKitGTK vulnerabilities2022-02-28
Red Hat
webkitgtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced2022-02-09
Apple
CVE-2022-22592: Safari 15.32022-01-26
Apple
CVE-2022-22592: watchOS 8.42022-01-26
Apple
CVE-2022-22592: iOS 15.3 and iPadOS 15.32022-01-26
CVE-2022-22592 (MEDIUM CVSS 6.5) | A logic issue was addressed with im | cvebase.io