Lucene search

K
nvd[email protected]NVD:CVE-2022-32923
HistoryNov 01, 2022 - 8:15 p.m.

CVE-2022-32923

2022-11-0120:15:19
web.nvd.nist.gov
1
jit issue
operating systems
safari
malicious web content
internal states

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

60.9%

A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.

Affected configurations

NVD
Node
applesafariRange<16.1
OR
appleipadosRange<15.7.1
OR
appleiphone_osRange<15.7.1
OR
appleiphone_osMatch16.0
OR
applemacosRange<13.0
OR
appletvosRange<16.1
OR
applewatchosRange<9.1

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

60.9%