SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-8790

Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.

MEDIUM 5.5EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.35% probability · 28th percentile
CISA KEV
Not listed
Weakness
CWE-922
Affected
apple/swift
Source
product-security@apple.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.