cvelist/2021/33xxx/CVE-2021-33595.json

104 lines
3.7 KiB
JSON
Raw Normal View History

2021-05-27 18:00:42 +00:00
{
"CVE_data_meta": {
2021-08-11 11:01:19 +00:00
"ASSIGNER": "cve-notifications-us@f-secure.com",
2021-05-27 18:00:42 +00:00
"ID": "CVE-2021-33595",
2021-08-11 11:01:19 +00:00
"STATE": "PUBLIC",
"TITLE": "F-Secure Safe browser for iOS vulnerable to Address Bar Spoofing"
2021-05-27 18:00:42 +00:00
},
2021-08-11 11:01:19 +00:00
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "F-Secure Mobile Security",
"version": {
"version_data": [
{
"platform": "iOS",
"version_affected": ">",
"version_name": "18.3x",
"version_value": "18.4x"
}
]
}
}
]
},
"vendor_name": "F-Secure"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
2021-05-27 18:00:42 +00:00
"description": {
"description_data": [
{
"lang": "eng",
2021-08-11 11:01:19 +00:00
"value": "A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote attacker can leverage this to perform address bar spoofing attack."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 3.5,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "F-Secure Safe browser for iOS vulnerable to Address Bar Spoofing"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"url": "https://www.f-secure.com/en/business/programs/vulnerability-reward-program/hall-of-fame",
"name": "https://www.f-secure.com/en/business/programs/vulnerability-reward-program/hall-of-fame"
},
{
"refsource": "MISC",
"url": "https://www.f-secure.com/en/business/support-and-downloads/security-advisories",
"name": "https://www.f-secure.com/en/business/support-and-downloads/security-advisories"
},
{
"refsource": "MISC",
"name": "https://www.f-secure.com/en/business/support-and-downloads/security-advisories/cve-2021-33595",
"url": "https://www.f-secure.com/en/business/support-and-downloads/security-advisories/cve-2021-33595"
2021-05-27 18:00:42 +00:00
}
]
2021-08-11 11:01:19 +00:00
},
"solution": [
{
"lang": "eng",
"value": "Upgrade to version 18.4.x or newer from the App Store "
}
],
"source": {
"discovery": "EXTERNAL"
2021-05-27 18:00:42 +00:00
}
}