CVE-2019-8625

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-8625
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-8625.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-8625
Downstream
Related
Published
2019-12-18T18:15:30Z
Modified
2025-10-07T23:38:19.601Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.

References

Affected packages

Git / github.com/webkit/webkit

Affected ranges

Type
GIT
Repo
https://github.com/webkit/webkit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Safari-606.*

Safari-606.1.26
Safari-606.1.27
Safari-606.1.28
Safari-606.1.28.1
Safari-606.1.29
Safari-606.1.30
Safari-606.1.31
Safari-606.1.32
Safari-606.1.32.1
Safari-606.1.33
Safari-606.1.34
Safari-606.1.35
Safari-606.1.36
Safari-606.1.36.1.1
Safari-606.1.36.1.2
Safari-606.1.36.1.3
Safari-606.1.36.1.4
Safari-606.1.36.1.5
Safari-606.1.36.1.6
Safari-606.1.36.1.7
Safari-606.1.36.1.8