VulnerabilityModified
CVE-2020-9995
Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.
MEDIUM 6.1EPSS 0.59%
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-601
- Affected
- apple/macos server
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT211932Vendor Advisory
- https://support.apple.com/en-us/HT211932Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.