{"api_version":"1","generated_at":"2026-07-23T11:01:16+00:00","cve":"CVE-2019-8791","urls":{"html":"https://cve.report/CVE-2019-8791","api":"https://cve.report/api/cve/CVE-2019-8791.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-8791","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-8791"},"summary":{"title":"CVE-2019-8791","description":"An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2019-12-18 18:15:00","updated_at":"2020-01-02 19:00:00"},"problem_types":["CWE-601"],"metrics":[],"references":[{"url":"https://support.apple.com/HT210744","name":"https://support.apple.com/HT210744","refsource":"MISC","tags":["Vendor Advisory"],"title":"About the security content of Shazam Android App Version 9.25.0 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/HT210745","name":"https://support.apple.com/HT210745","refsource":"MISC","tags":["Vendor Advisory"],"title":"Shazam iOS App バージョン 12.11.0 のセキュリティコンテンツについて - Apple サポート","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-8791","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-8791","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"8791","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"shazam","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"8791","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"shazam","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"8791","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"shazam","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"8791","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"shazam","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-8791","ASSIGNER":"product-security@apple.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Apple","product":{"product_data":[{"product_name":"Shazam-Android","version":{"version_data":[{"version_affected":"<","version_value":"Shazam Android App Version 9.25.0"}]}},{"product_name":"Shazam-iOS","version":{"version_data":[{"version_affected":"<","version_value":"Shazam iOS App Version 12.11.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Processing a maliciously crafted URL may lead to an open redirect"}]}]},"references":{"reference_data":[{"url":"https://support.apple.com/HT210744","refsource":"MISC","name":"https://support.apple.com/HT210744"},{"url":"https://support.apple.com/HT210745","refsource":"MISC","name":"https://support.apple.com/HT210745"}]},"description":{"description_data":[{"lang":"eng","value":"An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect."}]}},"nvd":{"publishedDate":"2019-12-18 18:15:00","lastModifiedDate":"2020-01-02 19:00:00","problem_types":["CWE-601"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apple:shazam:*:*:*:*:*:iphone_os:*:*","versionEndExcluding":"9.25.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apple:shazam:*:*:*:*:*:android:*:*","versionEndExcluding":"12.11.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"8791","Ordinal":"146627","Title":"CVE-2019-8791","CVE":"CVE-2019-8791","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"8791","Ordinal":"1","NoteData":"An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"8791","Ordinal":"2","NoteData":"2019-12-18","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"8791","Ordinal":"3","NoteData":"2019-12-18","Type":"Other","Title":"Modified"}]}}}