CVE Vulnerabilities

CVE-2024-23271

Published: Apr 24, 2024 | Modified: Dec 12, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
4.6 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, Safari 17.3, tvOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*17.3 (excluding)
IpadosApple*17.3 (excluding)
Iphone_osApple*17.3 (excluding)
MacosApple14.0 (including)14.3 (excluding)
TvosApple*17.3 (excluding)
WatchosApple*10.3 (excluding)
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatwebkitgtk4-0:2.48.3-2.el7_9*
Red Hat Enterprise Linux 8RedHatwebkit2gtk3-0:2.46.3-1.el8_10*
Red Hat Enterprise Linux 9RedHatwebkit2gtk3-0:2.42.5-1.el9*
Qtwebkit-opensource-srcUbuntudevel*
Qtwebkit-opensource-srcUbuntuesm-apps/bionic*
Qtwebkit-opensource-srcUbuntuesm-apps/focal*
Qtwebkit-opensource-srcUbuntuesm-apps/jammy*
Qtwebkit-opensource-srcUbuntuesm-apps/noble*
Qtwebkit-opensource-srcUbuntuesm-infra/xenial*
Qtwebkit-opensource-srcUbuntufocal*
Qtwebkit-opensource-srcUbuntujammy*
Qtwebkit-opensource-srcUbuntunoble*
Qtwebkit-sourceUbuntuesm-apps/bionic*
Qtwebkit-sourceUbuntuesm-apps/xenial*
Webkit2gtkUbuntuesm-infra/bionic*
Webkit2gtkUbuntuesm-infra/focal*
Webkit2gtkUbuntuesm-infra/xenial*
Webkit2gtkUbuntufocal*
Webkit2gtkUbuntujammy*
Webkit2gtkUbuntuupstream*
WebkitgtkUbuntuesm-apps/bionic*
WebkitgtkUbuntuesm-apps/xenial*
WpewebkitUbuntuesm-apps/focal*
WpewebkitUbuntuesm-apps/jammy*
WpewebkitUbuntufocal*
WpewebkitUbuntujammy*
WpewebkitUbuntuupstream*

References