CVE Vulnerabilities

CVE-2022-22594

Origin Validation Error

Published: Mar 18, 2022 | Modified: Mar 28, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 15.3 (excluding)
Ipados Apple * 15.3 (excluding)
Iphone_os Apple * 15.3 (excluding)
Macos Apple * 12.2 (excluding)
Tvos Apple * 15.3 (excluding)
Watchos Apple * 8.4 (excluding)

References