PT-2023-6792 · Apple+6 · Apple Macos+6
Gertjan Franken
·
Published
2023-03-27
·
Updated
2025-01-28
·
CVE-2023-32370
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
macOS versions prior to 13.3
WebKitGTK (affected versions not specified)
WPE WebKit (affected versions not specified)
Description
The issue is related to insufficient input validation, which may allow a remote attacker to impact data integrity. A logic issue was addressed with improved validation. The Content Security Policy to block domains with wildcards may fail.
Recommendations
For macOS versions prior to 13.3, update to macOS Ventura 13.3 to resolve the issue.
For WebKitGTK, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For WPE WebKit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Suse