ISOMAN

CVE

CVE-2018-4117

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://www.securityfocus.com/bid/104887
  2. http://www.securitytracker.com/id/1040604
  3. https://access.redhat.com/errata/RHSA-2018:2282
  4. https://security.gentoo.org/glsa/201808-01
  5. https://security.gentoo.org/glsa/201808-04
  6. https://support.apple.com/HT208693
  7. https://support.apple.com/HT208694
  8. https://support.apple.com/HT208695
  9. https://support.apple.com/HT208696
  10. https://support.apple.com/HT208697
  11. https://usn.ubuntu.com/3635-1/
  12. https://www.debian.org/security/2018/dsa-4256
  13. http://www.securityfocus.com/bid/104887
  14. http://www.securitytracker.com/id/1040604
  15. https://access.redhat.com/errata/RHSA-2018:2282
  16. https://security.gentoo.org/glsa/201808-01
  17. https://security.gentoo.org/glsa/201808-04
  18. https://support.apple.com/HT208693
  19. https://support.apple.com/HT208694
  20. https://support.apple.com/HT208695