CVE Vulnerabilities

CVE-2010-1760

Published: Aug 19, 2010 | Modified: Mar 18, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.

Affected Software

Name Vendor Start Version End Version
Webkit Apple * r58408 (including)
Webkit Apple r50173 (including) r50173 (including)
Webkit Apple r56187 (including) r56187 (including)
Webkit Apple r56188 (including) r56188 (including)
Webkit Apple r56379 (including) r56379 (including)

References