Lucene search

K
nvd[email protected]NVD:CVE-2023-41977
HistoryOct 25, 2023 - 7:15 p.m.

CVE-2023-41977

2023-10-2519:15:10
web.nvd.nist.gov
cve-2023-41977
caches handling
malicious website

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

3.5 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.4%

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14.1, iOS 16.7.2 and iPadOS 16.7.2. Visiting a malicious website may reveal browsing history.

Affected configurations

NVD
Node
appleipadosRange<16.7.2
OR
appleiphone_osRange<16.7.2
OR
applemacosRange14.014.1

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

3.5 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.4%