PT-2016-3904 · Apple · Swift3
Darryl Tam
+1
·
Published
2016-01-13
·
Updated
2016-12-01
·
CVE-2015-8466
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Swift3 versions prior to 1.9
Description
The issue allows remote attackers to conduct replay attacks. This is possible via an Authorization request that lacks a Date header.
Recommendations
For versions prior to 1.9, update to version 1.9 or later to resolve the issue. As a temporary workaround, consider ensuring all Authorization requests include a Date header to prevent replay attacks.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swift3