6.5

CVE-2018-4117

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari Version < 11.1
Apple ≫ iPhone OS Version < 11.3
Apple ≫ watchOS Version < 4.3
Apple ≫ iCloud Version < 7.4
   Microsoft ≫ Windows Version -
Apple ≫ iTunes Version < 12.7.4
   Microsoft ≫ Windows Version -
Webkitgtk ≫ Webkitgtk+ Version < 2.20.4
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.07% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.securitytracker.com/id/1040604
Third Party Advisory
VDB Entry
https://security.gentoo.org/glsa/201808-04
Third Party Advisory
https://support.apple.com/HT208693
Vendor Advisory
https://support.apple.com/HT208694
Vendor Advisory
https://support.apple.com/HT208695
Vendor Advisory
https://support.apple.com/HT208697
Vendor Advisory
https://usn.ubuntu.com/3635-1/
Third Party Advisory
https://support.apple.com/HT208696
Vendor Advisory
http://www.securityfocus.com/bid/104887
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:2282
Third Party Advisory
https://security.gentoo.org/glsa/201808-01
Third Party Advisory
https://www.debian.org/security/2018/dsa-4256
Third Party Advisory