Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32370
HistorySep 06, 2023 - 12:00 a.m.

CVE-2023-32370

2023-09-0600:00:00
ubuntu.com
ubuntu.com
16
logic issue
macos ventura 13.3
content security policy
wildcard domains
webkit
javascriptcore
webkit2gtk versions

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

30.9%

A logic issue was addressed with improved validation. This issue is fixed
in macOS Ventura 13.3. Content Security Policy to block domains with
wildcards may fail.

Notes

Author Note
jdstrand webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
mdeslaur It is no longer possible to build new webkit2gtk versions on focal and earlier. Marking as ignored.
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchwebkit2gtk< 2.40.4-0ubuntu0.22.04.1UNKNOWN
ubuntu23.04noarchwebkit2gtk< 2.40.1-0ubuntu0.23.04.1UNKNOWN

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

30.9%