CVE-2021-1825
Published: 8 September 2021
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
Notes
| Author | Note |
|---|---|
| jdstrand | webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8 |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
qtwebkit-opensource-src Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Ignored
|
|
| hirsute |
Ignored
(end of life)
|
|
| impish |
Ignored
(end of life)
|
|
| jammy |
Ignored
|
|
| kinetic |
Ignored
(end of life, was needs-triage)
|
|
| lunar |
Ignored
(end of life, was needs-triage)
|
|
| mantic |
Ignored
|
|
| noble |
Ignored
|
|
| trusty |
Does not exist
|
|
| upstream |
Ignored
|
|
| xenial |
Ignored
|
|
|
qtwebkit-source Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Does not exist
|
|
| hirsute |
Does not exist
|
|
| impish |
Does not exist
|
|
| jammy |
Does not exist
|
|
| kinetic |
Does not exist
|
|
| lunar |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| trusty |
Does not exist
|
|
| upstream |
Needs triage
|
|
| xenial |
Ignored
|
|
|
webkit2gtk Launchpad, Ubuntu, Debian |
bionic |
Released
(2.30.3-0ubuntu0.18.04.1)
|
| focal |
Released
(2.30.3-0ubuntu0.20.04.1)
|
|
| hirsute |
Released
(2.30.3-1)
|
|
| impish |
Released
(2.30.3-1)
|
|
| jammy |
Released
(2.30.3-1)
|
|
| kinetic |
Released
(2.30.3-1)
|
|
| lunar |
Released
(2.30.3-1)
|
|
| mantic |
Released
(2.30.3-1)
|
|
| noble |
Released
(2.30.3-1)
|
|
| trusty |
Does not exist
|
|
| upstream |
Released
(2.30.0)
|
|
| xenial |
Ignored
|
|
|
webkitgtk Launchpad, Ubuntu, Debian |
bionic |
Ignored
|
| focal |
Does not exist
|
|
| hirsute |
Does not exist
|
|
| impish |
Does not exist
|
|
| jammy |
Does not exist
|
|
| kinetic |
Does not exist
|
|
| lunar |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| trusty |
Does not exist
|
|
| upstream |
Needs triage
|
|
| xenial |
Ignored
|
|
|
wpewebkit Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
| focal |
Ignored
|
|
| hirsute |
Ignored
(end of life)
|
|
| impish |
Ignored
(end of life)
|
|
| jammy |
Ignored
|
|
| kinetic |
Does not exist
|
|
| lunar |
Does not exist
|
|
| mantic |
Does not exist
|
|
| noble |
Does not exist
|
|
| trusty |
Does not exist
|
|
| upstream |
Needs triage
|
|
| xenial |
Does not exist
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 6.1 |
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Changed |
| Confidentiality | Low |
| Integrity impact | Low |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |