Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-22637
HistoryJan 25, 2022 - 12:00 a.m.

CVE-2022-22637

2022-01-2500:00:00
ubuntu.com
ubuntu.com
20

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

71.1%

A logic issue was addressed with improved state management. This issue is
fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS
15.4, tvOS 15.4. A malicious website may cause unexpected cross-origin
behavior.

Notes

Author Note
jdstrand webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchwebkit2gtk< 2.36.0-0ubuntu0.20.04.3UNKNOWN
ubuntu21.10noarchwebkit2gtk< 2.36.0-0ubuntu0.21.10.3UNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

71.1%