CVE-2024-44228
published 2024-10-28CVE-2024-44228: This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.41%
33.7th percentile
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 16 | 16 |
| apple | xcode | < 16.0 | 16.0 |
| apple | xcode | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-44228: Xcode 16
vendor_apple·2024-09-16·CVSS 7.5
CVE-2024-44228 [HIGH] CVE-2024-44228: Xcode 16
Apple Security Update: About the security content of Xcode 16
Product: Xcode
Version: 16
CVE: CVE-2024-44228
Component: Playgrounds
Impact: An app may be able to inherit Xcode permissions and access user data
Description: This issue was addressed with improved permissions checking.
GHSA
GHSA-rj6f-j453-ffwx: This issue was addressed with improved permissions checking
ghsa_unreviewed·2024-10-28
CVE-2024-44228 [HIGH] CWE-276 GHSA-rj6f-j453-ffwx: This issue was addressed with improved permissions checking
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|upper|3a|j"; nocase; fast_pattern; content:"n"; within:12; content:"d"; within:12; content:"i"; within:12; reference:cve,2021-44228; classtype:attempted-admin; sid:2034810; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|lower|3a|j"; nocase; fast_pattern; content:"n"; within:12; content:"d"; within:12; content:"i"; within:12; reference:cve,2021-44228; classtype:attempted-admin; sid:2034808; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|3a 2f 2f|"; within:20; reference:cve,2021-44228; classtype:misc-activity; sid:2034784; rev:3; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, reviewed_at 2024_05_07, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|3a 2f 2f|"; within:20; reference:cve,2021-44228; classtype:misc-activity; sid:2034662; rev:3; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
2024-10-28
Published