Lucene search

K
redhatcveRedhat.comRH:CVE-2024-23222
HistoryJan 24, 2024 - 12:25 p.m.

CVE-2024-23222

2024-01-2412:25:02
redhat.com
access.redhat.com
26
flaw
webkitgtk
remote code execution
type confusion issue
vulnerability
actively exploited
cisa
kev catalog
mitigation

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

EPSS

0.001

Percentile

45.0%

A flaw was found in WebKitGTK. Processing malicious web content may lead to remote code execution due to a type confusion issue. This vulnerability is known to be actively exploited in the wild and was included in the CISA’s KEV catalog.

Mitigation

Do not process or load untrusted web content. Please update the affected package as soon as possible.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

EPSS

0.001

Percentile

45.0%