CVE Vulnerabilities

CVE-2023-40451

Published: Sep 27, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*17.0 (excluding)
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatwebkitgtk4-0:2.48.3-2.el7_9*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:2.40.5-1.el8*
Red Hat Enterprise Linux 9RedHatwebkit2gtk3-0:2.40.5-1.el9*
Qtwebkit-opensource-srcUbuntubionic*
Qtwebkit-opensource-srcUbuntudevel*
Qtwebkit-opensource-srcUbuntuesm-apps/bionic*
Qtwebkit-opensource-srcUbuntuesm-apps/focal*
Qtwebkit-opensource-srcUbuntuesm-apps/jammy*
Qtwebkit-opensource-srcUbuntuesm-apps/noble*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntufocal*
Qtwebkit-opensource-srcUbuntujammy*
Qtwebkit-opensource-srcUbuntulunar*
Qtwebkit-opensource-srcUbuntumantic*
Qtwebkit-opensource-srcUbuntunoble*
Qtwebkit-opensource-srcUbuntutrusty*
Qtwebkit-opensource-srcUbuntuupstream*
Qtwebkit-opensource-srcUbuntuxenial*
Qtwebkit-sourceUbuntubionic*
Qtwebkit-sourceUbuntuesm-apps/bionic*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Qtwebkit-sourceUbuntutrusty*
Qtwebkit-sourceUbuntuxenial*
Webkit2gtkUbuntubionic*
Webkit2gtkUbuntudevel*
Webkit2gtkUbuntuesm-infra/bionic*
Webkit2gtkUbuntuesm-infra/focal*
Webkit2gtkUbuntuesm-infra/xenial*
Webkit2gtkUbuntufocal*
Webkit2gtkUbuntujammy*
Webkit2gtkUbuntulunar*
Webkit2gtkUbuntumantic*
Webkit2gtkUbuntunoble*
Webkit2gtkUbuntuupstream*
Webkit2gtkUbuntuxenial*
WebkitgtkUbuntubionic*
WebkitgtkUbuntuesm-apps/bionic*
WebkitgtkUbuntuesm-apps/xenial*
WebkitgtkUbuntutrusty*
WebkitgtkUbuntuxenial*
WpewebkitUbuntubionic*
WpewebkitUbuntuesm-apps/focal*
WpewebkitUbuntuesm-apps/jammy*
WpewebkitUbuntufocal*
WpewebkitUbuntujammy*
WpewebkitUbuntutrusty*
WpewebkitUbuntuxenial*

References