7.5

CVE-2022-22585

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access a user's files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 15.3
Apple ≫ iPhone OS Version < 15.3
Apple ≫ macOS Version < 11.6.3
Apple ≫ macOS Version >= 12.0.0 < 12.2
Apple ≫ tvOS Version < 15.3
Apple ≫ watchOS Version < 8.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.65% 0.743
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://support.apple.com/en-us/HT213055
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213053
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213054
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213057
Vendor Advisory
Release Notes
https://support.apple.com/en-us/HT213059
Vendor Advisory
Release Notes