CVE-2020-3902
Summary
| CVE | CVE-2020-3902 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-01 18:15:00 UTC |
| Updated | 2022-06-02 18:43:00 UTC |
| Description | An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to a cross site scripting attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About the security content of iCloud for Windows 10.9.3 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| About the security content of iTunes 12.10.5 for Windows - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| About the security content of iOS 13.4 and iPadOS 13.4 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| About the security content of tvOS 13.4 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| About the security content of Safari 13.1 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| About the security content of iCloud for Windows 7.18 - Apple Support |
MISC |
support.apple.com |
Release Notes, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296073 Oracle Solaris 11.4 Support Repository Update (SRU) 24.75.2 Missing (CPUJUL2020)
- 377553 Alibaba Cloud Linux Security Update for webkitgtk4 (ALINUX2-SA-2020:0147)
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940362 AlmaLinux Security Update for GNOME (ALSA-2020:4451)
- 960761 Rocky Linux Security Update for GNOME (RLSA-2020:4451)