{"api_version":"1","generated_at":"2026-07-23T08:39:14+00:00","cve":"CVE-2019-8790","urls":{"html":"https://cve.report/CVE-2019-8790","api":"https://cve.report/api/cve/CVE-2019-8790.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-8790","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-8790"},"summary":{"title":"CVE-2019-8790","description":"This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2020-10-27 20:15:00","updated_at":"2020-11-03 15:03:00"},"problem_types":["CWE-922"],"metrics":[],"references":[{"url":"https://support.apple.com/en-us/HT210647","name":"https://support.apple.com/en-us/HT210647","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"About the security content of Swift 5.1.1 for Ubuntu - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-8790","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-8790","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"8790","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"swift","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"ubuntu","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"8790","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"swift","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"ubuntu","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-8790","ASSIGNER":"product-security@apple.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Apple","product":{"product_data":[{"product_name":"Swift for Ubuntu","version":{"version_data":[{"version_affected":"<","version_value":"5.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://support.apple.com/en-us/HT210647","name":"https://support.apple.com/en-us/HT210647"}]},"description":{"description_data":[{"lang":"eng","value":"This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure."}]}},"nvd":{"publishedDate":"2020-10-27 20:15:00","lastModifiedDate":"2020-11-03 15:03:00","problem_types":["CWE-922"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apple:swift:*:*:*:*:*:ubuntu:*:*","versionEndExcluding":"5.1.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"8790","Ordinal":"146626","Title":"CVE-2019-8790","CVE":"CVE-2019-8790","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"8790","Ordinal":"1","NoteData":"This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"8790","Ordinal":"2","NoteData":"2020-10-27","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"8790","Ordinal":"3","NoteData":"2020-10-27","Type":"Other","Title":"Modified"}]}}}