CVE-2023-40451
published 2023-09-27CVE-2023-40451: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.96%
57.7th percentile
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | < 17.0 | 17.0 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 17 | 17 |
| debian | webkit2gtk | < webkit2gtk 2.40.5-1~deb12u1 (bookworm) | webkit2gtk 2.40.5-1~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.40.5-1~deb12u1 (bookworm) | webkit2gtk 2.40.5-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code
vendor_redhat·2023-09-28·CVSS 8.8
CVE-2023-40451 [HIGH] webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code
webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
A flaw was found in WebKitGTK. An attacker may be able to execute JavaScript code to trigger Remote Code Execution, resulting in a high impact on data confidentiality, integrity, and system availability.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Out of support scope
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Out of support scope
Apple
CVE-2023-40451: Safari 17
vendor_apple·2023-09-26·CVSS 8.8
CVE-2023-40451 [HIGH] CVE-2023-40451: Safari 17
Apple Security Update: About the security content of Safari 17
Product: Safari
Version: 17
CVE: CVE-2023-40451
Component: WebKit
Impact: An attacker with JavaScript execution may be able to execute arbitrary code
Description: This issue was addressed with improved iframe sandbox enforcement.
Debian
CVE-2023-40451: webkit2gtk - This issue was addressed with improved iframe sandbox enforcement. This issue is...
vendor_debian·2023·CVSS 8.8
CVE-2023-40451 [HIGH] CVE-2023-40451: webkit2gtk - This issue was addressed with improved iframe sandbox enforcement. This issue is...
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 2.40.5-1~deb12u1)
bullseye: resolved (fixed in 2.40.5-1~deb11u1)
forky: resolved (fixed in 2.40.5-1)
sid: resolved (fixed in 2.40.5-1)
trixie: resolved (fixed in 2.40.5-1)
GHSA
GHSA-p489-ffhp-rw3f: This issue was addressed with improved iframe sandbox enforcement
ghsa_unreviewed·2023-09-27
CVE-2023-40451 [HIGH] GHSA-p489-ffhp-rw3f: This issue was addressed with improved iframe sandbox enforcement
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
OSV
CVE-2023-40451: This issue was addressed with improved iframe sandbox enforcement
osv·2023-09-27·CVSS 8.8
CVE-2023-40451 [HIGH] CVE-2023-40451: This issue was addressed with improved iframe sandbox enforcement
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2023/Oct/2http://www.openwall.com/lists/oss-security/2023/09/28/3https://security.gentoo.org/glsa/202401-33https://support.apple.com/en-us/HT213941http://seclists.org/fulldisclosure/2023/Oct/2http://www.openwall.com/lists/oss-security/2023/09/28/3https://security.gentoo.org/glsa/202401-33https://support.apple.com/en-us/HT213941https://webkitgtk.org/security/WSA-2023-0009.html
2023-09-27
Published