2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2023-23506" ,
"sourceIdentifier" : "product-security@apple.com" ,
"published" : "2023-02-27T20:15:13.817" ,
2023-07-27 02:00:32 +00:00
"lastModified" : "2023-07-27T01:15:11.893" ,
"vulnStatus" : "Modified" ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
2023-07-27 02:00:32 +00:00
"value" : "This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Ventura 13.2. An HTML document may be able to render iframes with sensitive user information."
2023-04-24 12:24:31 +02:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.5 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "13.2" ,
"matchCriteriaId" : "362E766C-05AD-4205-85FA-F388DDF5DD1A"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://support.apple.com/en-us/HT213605" ,
"source" : "product-security@apple.com" ,
"tags" : [
"Vendor Advisory"
]
}
]
}