CVE Vulnerabilities

CVE-2019-8827

Published: Oct 27, 2020 | Modified: Oct 29, 2020
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a user has visited.

Affected Software

Name Vendor Start Version End Version
Icloud Apple * 7.15 (excluding)
Icloud Apple 10.0 (including) 10.9.2 (excluding)
Itunes Apple * 12.10.2 (excluding)
Safari Apple * 13.0.3 (excluding)
Ipados Apple * 13.2 (excluding)
Iphone_os Apple * 13.2 (excluding)
Tvos Apple * 13.2 (excluding)

References