CVE-2024-27821Path Traversal in Apple IOS AND Ipados

CWE-22Path Traversal6 documents4 sources
Severity
4.7MEDIUMNVD
EPSS
2.4%
top 15.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may output sensitive user data without consent.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages7 packages

CVEListV5apple/macos< 14.5
NVDapple/macos14.014.5
NVDapple/ipados< 17.5
CVEListV5apple/watchos< 10.5
NVDapple/watchos< 10.5

🔴Vulnerability Details

2
GHSA
GHSA-69wv-v57r-pj37: A path handling issue was addressed with improved validation2024-05-14
CVEList
CVE-2024-27821: A path handling issue was addressed with improved validation2024-05-13

📋Vendor Advisories

3
Apple
CVE-2024-27821: iOS 17.5 and iPadOS 17.52024-05-13
Apple
CVE-2024-27821: watchOS 10.52024-05-13
Apple
CVE-2024-27821: macOS Sonoma 14.52024-05-13
CVE-2024-27821 — Path Traversal in Apple IOS AND Ipados | cvebase