CVE Vulnerabilities

CVE-2024-44187

Origin Validation Error

Published: Sep 17, 2024 | Modified: Sep 25, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

A cross-origin issue existed with iframe elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 18.0 (excluding)
Ipados Apple * 18.0 (excluding)
Iphone_os Apple * 18.0 (excluding)
Macos Apple * 15.0 (excluding)
Tvos Apple * 18.0 (excluding)
Visionos Apple * 2.0 (excluding)
Watchos Apple * 11.0 (excluding)
Red Hat Enterprise Linux 8 RedHat webkit2gtk3-0:2.46.3-1.el8_10 *
Red Hat Enterprise Linux 9 RedHat webkit2gtk3-0:2.46.1-2.el9_4 *
Red Hat Enterprise Linux 9 RedHat webkit2gtk3-0:2.46.3-1.el9_5 *
Qtwebkit-opensource-src Ubuntu devel *
Qtwebkit-opensource-src Ubuntu esm-apps/bionic *
Qtwebkit-opensource-src Ubuntu esm-apps/focal *
Qtwebkit-opensource-src Ubuntu esm-apps/jammy *
Qtwebkit-opensource-src Ubuntu esm-apps/noble *
Qtwebkit-opensource-src Ubuntu esm-infra/xenial *
Qtwebkit-opensource-src Ubuntu focal *
Qtwebkit-opensource-src Ubuntu jammy *
Qtwebkit-opensource-src Ubuntu noble *
Qtwebkit-opensource-src Ubuntu oracular *
Qtwebkit-source Ubuntu esm-apps/bionic *
Qtwebkit-source Ubuntu esm-apps/xenial *
Webkit2gtk Ubuntu devel *
Webkit2gtk Ubuntu esm-infra/bionic *
Webkit2gtk Ubuntu esm-infra/xenial *
Webkit2gtk Ubuntu focal *
Webkit2gtk Ubuntu jammy *
Webkit2gtk Ubuntu noble *
Webkit2gtk Ubuntu oracular *
Webkit2gtk Ubuntu upstream *
Webkitgtk Ubuntu esm-apps/bionic *
Webkitgtk Ubuntu esm-apps/xenial *
Wpewebkit Ubuntu esm-apps/focal *
Wpewebkit Ubuntu esm-apps/jammy *
Wpewebkit Ubuntu focal *
Wpewebkit Ubuntu jammy *

References