4.3
CVE-2024-54540
- EPSS 0.21%
- Veröffentlicht 15.01.2025 20:15:28
- Zuletzt bearbeitet 24.03.2025 18:15:20
- Erkennungen
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Music Version < 1.5.0.152
Microsoft ≫ Windows 10 22h2 Version - HwPlatform x64
Microsoft ≫ Windows 10 22h2 Version - HwPlatform x86
Microsoft ≫ Windows 11 24h2 Version - HwPlatform arm64
Microsoft ≫ Windows 10 22h2 Version - HwPlatform x86
Microsoft ≫ Windows 11 24h2 Version - HwPlatform arm64
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.116 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
| CISA-ADP | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://support.apple.com/en-us/122043