cbcvebase.
CVE-2024-23280
published 2024-03-08

CVE-2024-23280: An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.

Affected

20 ranges
VendorProductVersion rangeFixed in
appleios_17.4_and_ipados
appleios_and_ipados< 17.417.4
appleipad_os< 17.417.4
appleiphone_os< 17.417.4
applemacos< 14.414.4
applemacos>= 14.0 < 14.414.4
applemacos_sonoma
applesafari< 17.417.4
applesafari
appletvos< 17.417.4
appletvos
applewatchos< 10.410.4
applewatchos
debianwebkit2gtk< webkit2gtk 2.44.1-1~deb12u1 (bookworm)webkit2gtk 2.44.1-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.44.1-1~deb12u1 (bookworm)webkit2gtk 2.44.1-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
webkitgtkwebkitgtk< 2.44.02.44.0
wpewebkitwpe_webkit< 2.44.02.44.0

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM