CVE-2020-9925

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-9925
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-9925.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-9925
Related
Published
2020-10-16T17:15:17Z
Modified
2024-09-18T01:00:21Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may lead to universal cross site scripting.

References

Affected packages

Debian:11 / webkit2gtk

Package

Name
webkit2gtk
Purl
pkg:deb/debian/webkit2gtk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / webkit2gtk

Package

Name
webkit2gtk
Purl
pkg:deb/debian/webkit2gtk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / webkit2gtk

Package

Name
webkit2gtk
Purl
pkg:deb/debian/webkit2gtk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / wpewebkit

Package

Name
wpewebkit
Purl
pkg:deb/debian/wpewebkit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / wpewebkit

Package

Name
wpewebkit
Purl
pkg:deb/debian/wpewebkit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / wpewebkit

Package

Name
wpewebkit
Purl
pkg:deb/debian/wpewebkit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.28.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}