SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-2797

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading…

MEDIUM 5.0EPSS 3.58%

Does this matter?

Lower severity and a low EPSS score (3.58%). Track it; it rarely justifies an emergency change on its own.

Description

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.58% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
apple/iphone os · canonical/ubuntu linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.