CVE-2022-22662
published 2022-05-26CVE-2022-22662: A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.26%
66.3th percentile
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.4_and_ipados | — | — |
| apple | itunes_12.12.3_for_windows | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.5 | 11.6.5 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 2022 | 2022 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-003_catalina | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| debian | webkit2gtk | < webkit2gtk 2.36.0-1 (bookworm) | webkit2gtk 2.36.0-1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.36.0-1 (bookworm) | webkit2gtk 2.36.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: Cookie management issue leading to sensitive user information disclosure
vendor_redhat·2022-07-05·CVSS 6.5
CVE-2022-22662 [MEDIUM] CWE-200 webkitgtk: Cookie management issue leading to sensitive user information disclosure
webkitgtk: Cookie management issue leading to sensitive user information disclosure
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
A vulnerability was found in WebKitGTK, where an issue occurs due to improper cookie management. This flaw allows a remote attacker to trick the victim into parsing maliciously crafted web content, triggering the vulnerability and gaining access to potentially sensitive information.
Statement: Red Hat Enterprise Linux 6, 7, 8, and 9 are affected because the code-base is affected by this vulnerability.
Since Red Hat Enterprise Linux 6 and 7 are Out-of-Support-Scope for Low/
Apple
CVE-2022-22662: tvOS 15.4
vendor_apple·2022-03-14·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: tvOS 15.4
Apple Security Update: About the security content of tvOS 15.4
Product: tvOS
Version: 15.4
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22662: macOS Big Sur 11.6.5
vendor_apple·2022-03-14·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: macOS Big Sur 11.6.5
Apple Security Update: About the security content of macOS Big Sur 11.6.5
Product: macOS Big Sur
Version: 11.6.5
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22662: Security Update 2022-003 Catalina
vendor_apple·2022-03-14·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: Security Update 2022-003 Catalina
Apple Security Update: About the security content of Security Update 2022-003 Catalina
Product: Security Update 2022-003 Catalina
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22662: iOS 15.4 and iPadOS 15.4
vendor_apple·2022-03-14·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: iOS 15.4 and iPadOS 15.4
Apple Security Update: About the security content of iOS 15.4 and iPadOS 15.4
Product: iOS 15.4 and iPadOS
Version: 15.4
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22662: watchOS 8.5
vendor_apple·2022-03-14·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: watchOS 8.5
Apple Security Update: About the security content of watchOS 8.5
Product: watchOS
Version: 8.5
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22662: macOS Monterey 12.3
vendor_apple·2022-03-14·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: macOS Monterey 12.3
Apple Security Update: About the security content of macOS Monterey 12.3
Product: macOS Monterey
Version: 12.3
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Apple
CVE-2022-22662: iTunes 12.12.3 for Windows
vendor_apple·2022-03-08·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: iTunes 12.12.3 for Windows
Apple Security Update: About the security content of iTunes 12.12.3 for Windows
Product: iTunes 12.12.3 for Windows
CVE: CVE-2022-22662
Component: WebKit
Impact: Processing maliciously crafted web content may disclose sensitive user information
Description: A cookie management issue was addressed with improved state management.
Debian
CVE-2022-22662: webkit2gtk - A cookie management issue was addressed with improved state management. This iss...
vendor_debian·2022·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: webkit2gtk - A cookie management issue was addressed with improved state management. This iss...
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
Scope: local
bookworm: resolved (fixed in 2.36.0-1)
bullseye: resolved (fixed in 2.36.0-3~deb11u1)
forky: resolved (fixed in 2.36.0-1)
sid: resolved (fixed in 2.36.0-1)
trixie: resolved (fixed in 2.36.0-1)
GHSA
GHSA-83p3-v4fm-fxh5: A cookie management issue was addressed with improved state management
ghsa_unreviewed·2022-05-27
CVE-2022-22662 [MEDIUM] CWE-668 GHSA-83p3-v4fm-fxh5: A cookie management issue was addressed with improved state management
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
OSV
CVE-2022-22662: A cookie management issue was addressed with improved state management
osv·2022-05-26·CVSS 6.5
CVE-2022-22662 [MEDIUM] CVE-2022-22662: A cookie management issue was addressed with improved state management
A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may disclose sensitive user information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/07/05/3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33BWWAQLLBHKGSI332ZZCORTFZ2XLOIH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANNHXXARVBRGI74TVQNZOAG6P7AGSMUJ/https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213184https://support.apple.com/en-us/HT213185http://www.openwall.com/lists/oss-security/2022/07/05/3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33BWWAQLLBHKGSI332ZZCORTFZ2XLOIH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ANNHXXARVBRGI74TVQNZOAG6P7AGSMUJ/https://security.gentoo.org/glsa/202208-39https://support.apple.com/en-us/HT213184https://support.apple.com/en-us/HT213185
2022-05-26
Published