VulnerabilityModified
CVE-2019-8827
The HTTP referrer header may be used to leak browsing history.
MEDIUM 4.3EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
The HTTP referrer header may be used to leak browsing history. The issue was resolved by downgrading all third party referrers to their origin. This issue is fixed in Safari 13.0.3, iTunes 12.10.2 for Windows, iCloud for Windows 10.9.2, tvOS 13.2, iOS 13.2 and iPadOS 13.2, iCloud for Windows 7.15. Visiting a maliciously crafted website may reveal the sites a user has visited.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- apple/icloud · apple/itunes · apple/safari · apple/ipados · apple/iphone os · apple/tvos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT210721Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210723Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210725Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210726Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210728Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210947Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210721Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210723Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210725Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210726Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210728Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210947Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.