PT-2016-3904 · Apple · Swift3

Darryl Tam

+1

·

Publicado

2016-01-13

·

Atualizado

2016-12-01

·

CVE-2015-8466

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Swift3 versions prior to 1.9
Description The issue allows remote attackers to conduct replay attacks. This is possible via an Authorization request that lacks a Date header.
Recommendations For versions prior to 1.9, update to version 1.9 or later to resolve the issue. As a temporary workaround, consider ensuring all Authorization requests include a Date header to prevent replay attacks.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8466
DSA-3583-1

Produtos afetados

Swift3