PT-2020-11316 · Apple · Ipados+9
Rob Sayre
+1
·
Published
2020-10-27
·
Updated
2020-10-30
·
CVE-2019-8834
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apple tvOS versions prior to 13.3
Apple watchOS versions prior to 6.1.1
Apple iCloud for Windows versions prior to 10.9
Apple macOS Catalina versions prior to 10.15.2
Apple macOS Mojave versions prior to Security Update 2019-002
Apple macOS High Sierra versions prior to Security Update 2019-007
Apple iOS versions prior to 13.3
Apple iPadOS versions prior to 13.3
Apple iTunes for Windows versions prior to 12.10.3
Apple iCloud for Windows versions prior to 7.16
Description
A configuration issue was addressed with additional restrictions. An attacker in a privileged network position may be able to bypass HSTS for a limited number of specific top-level domains previously not in the HSTS preload list.
Recommendations
For Apple tvOS versions prior to 13.3, update to tvOS 13.3 or later.
For Apple watchOS versions prior to 6.1.1, update to watchOS 6.1.1 or later.
For Apple iCloud for Windows versions prior to 10.9, update to iCloud for Windows 10.9 or later.
For Apple macOS Catalina versions prior to 10.15.2, update to macOS Catalina 10.15.2 or later.
For Apple macOS Mojave versions prior to Security Update 2019-002, apply Security Update 2019-002 or later.
For Apple macOS High Sierra versions prior to Security Update 2019-007, apply Security Update 2019-007 or later.
For Apple iOS versions prior to 13.3, update to iOS 13.3 or later.
For Apple iPadOS versions prior to 13.3, update to iPadOS 13.3 or later.
For Apple iTunes for Windows versions prior to 12.10.3, update to iTunes 12.10.3 for Windows or later.
For Apple iCloud for Windows versions prior to 7.16, update to iCloud for Windows 7.16 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Icloud For Windows
Ios
Ipados
Itunes
Itunes For Windows
Macos Catalina
Macos High Sierra
Macos Mojave
Tvos
Watchos