VulnerabilityModified
CVE-2019-8632
An attacker in a privileged network position may be able to intercept analytics data.
MEDIUM 6.5EPSS 1.29%
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be able to intercept analytics data.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- apple/texture
- Source
- product-security@apple.com
References
- https://support.apple.com/HT210110Vendor Advisory
- https://support.apple.com/HT210111Vendor Advisory
- https://www.info-sec.ca/advisories/Texture.htmlThird Party Advisory
- https://support.apple.com/HT210110Vendor Advisory
- https://support.apple.com/HT210111Vendor Advisory
- https://www.info-sec.ca/advisories/Texture.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.