Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-32933
HistoryJun 10, 2024 - 12:00 a.m.

CVE-2022-32933

2024-06-1000:00:00
ubuntu.com
ubuntu.com
24
cve-2022-32933
webkit
ubuntu
javascriptcore
focal
webkit2gtk

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.1%

An information disclosure issue was addressed by removing the vulnerable
code. This issue is fixed in macOS Monterey 12.5. A website may be able to
track the websites a user visited in Safari private browsing mode.

Notes

Author Note
jdstrand webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
mdeslaur It is no longer possible to build new webkit2gtk versions on focal and earlier. Marking as ignored.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.1%