CVE-2020-9952
Published on: 10/16/2020 12:00:00 AM UTC
Last Modified on: 01/09/2023 04:41:00 PM UTC
Certain versions of Icloud from Apple contain the following vulnerability:
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0, watchOS 7.0, Safari 14.0, iCloud for Windows 11.4, iCloud for Windows 7.21. Processing maliciously crafted web content may lead to a cross site scripting attack.
- CVE-2020-9952 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.1 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | LOW |
CVSS2 Score: 5.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
About the security content of iCloud for Windows 7.21 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
About the security content of iOS 14.0 and iPadOS 14.0 - Apple Support | Vendor Advisory support.apple.com text/html |
![]() |
About the security content of watchOS 7.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
Full Disclosure: APPLE-SA-2020-11-13-6 Additional information for APPLE-SA-2020-09-16-4 watchOS 7.0 | Mailing List Third Party Advisory seclists.org text/html |
![]() |
oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2020-0008 | Mailing List www.openwall.com text/html |
![]() |
About the security content of tvOS 14.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
Full Disclosure: APPLE-SA-2020-11-13-5 Additional information for APPLE-SA-2020-09-16-3 Safari 14.0 | Mailing List Third Party Advisory seclists.org text/html |
![]() |
WebkitGTK+: Multiple vulnerabilities (GLSA 202012-10) — Gentoo security | security.gentoo.org text/html |
![]() |
Full Disclosure: APPLE-SA-2020-11-13-4 Additional information for APPLE-SA-2020-09-16-2 tvOS 14.0 | Mailing List Third Party Advisory seclists.org text/html |
![]() |
About the security content of Safari 14.0 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
Full Disclosure: APPLE-SA-2020-11-13-3 Additional information for APPLE-SA-2020-09-16-1 iOS 14.0 and iPadOS 14.0 | Mailing List Third Party Advisory seclists.org text/html |
![]() |
About the security content of iCloud for Windows 11.4 - Apple Support | Release Notes Vendor Advisory support.apple.com text/html |
![]() |
Related QID Numbers
- 501707 Alpine Linux Security Update for webkit2gtk
- 751623 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0142-1)
- 751646 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0183-1)
- 751648 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:0182-1)
- 751659 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-1)
- 751755 OpenSUSE Security Update for webkit2gtk3 (openSUSE-SU-2022:0182-2)
- 960761 Rocky Linux Security Update for GNOME (RLSA-2020:4451)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apple | Icloud | All | All | All | All |
Application | Apple | Icloud | All | All | All | All |
Operating System | Apple | Ipados | All | All | All | All |
Operating System | Apple | Ipad Os | All | All | All | All |
Operating System | Apple | Ipad Os | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Operating System | Apple | Iphone Os | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Application | Apple | Safari | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Tvos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
Operating System | Apple | Watchos | All | All | All | All |
Application | Webkit | Webkitgtk | All | All | All | All |
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:*:
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*:
- cpe:2.3:a:webkit:webkitgtk\+:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Severity: ?? | An input validation issue was addressed ... | CVE-2020-9952 | Link for more: alerts.remotelyrmm.com/CVE-2020-9952 | 2022-07-23 11:29:15 |