{"api_version":"1","generated_at":"2026-07-23T08:05:17+00:00","cve":"CVE-2017-7142","urls":{"html":"https://cve.report/CVE-2017-7142","api":"https://cve.report/api/cve/CVE-2017-7142.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7142","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7142"},"summary":{"title":"CVE-2017-7142","description":"An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the \"WebKit Storage\" component. It allows attackers to bypass the Safari Private Browsing protection mechanism, and consequently obtain sensitive information about visited web sites.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2017-10-23 01:29:00","updated_at":"2017-10-26 18:19:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://support.apple.com/HT208116","name":"https://support.apple.com/HT208116","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"About the security content of Safari 11 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1039384","name":"1039384","refsource":"SECTRACK","tags":["Third Party Advisory","VDB Entry"],"title":"Apple Safari Input Validation Bugs Let Remote Users Spoof the Address Bar and Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100996","name":"100996","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7142","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7142","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7142","vulnerable":"1","versionEndIncluding":"10.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"product-security@apple.com","ID":"CVE-2017-7142","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the \"WebKit Storage\" component. It allows attackers to bypass the Safari Private Browsing protection mechanism, and consequently obtain sensitive information about visited web sites."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1039384","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1039384"},{"name":"100996","refsource":"BID","url":"http://www.securityfocus.com/bid/100996"},{"name":"https://support.apple.com/HT208116","refsource":"CONFIRM","url":"https://support.apple.com/HT208116"}]}},"nvd":{"publishedDate":"2017-10-23 01:29:00","lastModifiedDate":"2017-10-26 18:19:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndIncluding":"10.1.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7142","Ordinal":"103837","Title":"CVE-2017-7142","CVE":"CVE-2017-7142","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7142","Ordinal":"1","NoteData":"An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the \"WebKit Storage\" component. It allows attackers to bypass the Safari Private Browsing protection mechanism, and consequently obtain sensitive information about visited web sites.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"7142","Ordinal":"2","NoteData":"2017-10-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7142","Ordinal":"3","NoteData":"2017-10-23","Type":"Other","Title":"Modified"}]}}}