2023-09-06 04:00:28 +00:00
{
"id" : "CVE-2023-32370" ,
"sourceIdentifier" : "product-security@apple.com" ,
"published" : "2023-09-06T02:15:09.070" ,
2024-01-05 15:00:28 +00:00
"lastModified" : "2024-01-05T14:15:46.447" ,
"vulnStatus" : "Modified" ,
2023-09-06 04:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail."
2024-01-05 15:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se abord\u00f3 un problema de l\u00f3gica con una comprobaci\u00f3n mejorada. Este problema es corregido en macOS Ventura 13.3. La pol\u00edtica de seguridad de contenido para bloquear dominios con wildcards podr\u00eda fallar."
2023-09-06 04:00:28 +00:00
}
] ,
2023-09-08 16:00:28 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "13.0" ,
"versionEndExcluding" : "13.3" ,
"matchCriteriaId" : "A6D636F7-278A-491B-8960-91A4D5A86A96"
}
]
}
]
2023-10-15 04:00:26 +00:00
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.40.1" ,
"matchCriteriaId" : "A007F029-38D8-4D0D-8DF2-A2F6CB9ADE60"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "2.40.1" ,
"matchCriteriaId" : "8C1E75F9-1855-4668-8E78-2A6F0F4FCBA1"
}
]
}
]
2023-09-08 16:00:28 +00:00
}
] ,
2023-09-06 04:00:28 +00:00
"references" : [
2023-09-11 20:00:29 +00:00
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/11/1" ,
2023-10-15 04:00:26 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
2023-09-11 20:00:29 +00:00
} ,
2024-01-05 15:00:28 +00:00
{
"url" : "https://security.gentoo.org/glsa/202401-04" ,
"source" : "product-security@apple.com"
} ,
2023-09-06 04:00:28 +00:00
{
"url" : "https://support.apple.com/en-us/HT213670" ,
2023-09-08 16:00:28 +00:00
"source" : "product-security@apple.com" ,
"tags" : [
"Release Notes" ,
"Vendor Advisory"
]
2023-09-06 04:00:28 +00:00
}
]
}