CVE-2023-42843

A

n inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:14.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*

History

09 Dec 2024, 17:31

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/03/26/1 - () http://www.openwall.com/lists/oss-security/2024/03/26/1 - Mailing List, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/[email protected]/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/ - () https://lists.fedoraproject.org/archives/list/[email protected]/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/ - Mailing List
References () https://support.apple.com/en-us/HT213981 - () https://support.apple.com/en-us/HT213981 - Vendor Advisory
References () https://support.apple.com/en-us/HT213982 - () https://support.apple.com/en-us/HT213982 - Vendor Advisory
References () https://support.apple.com/en-us/HT213984 - () https://support.apple.com/en-us/HT213984 - Vendor Advisory
References () https://support.apple.com/en-us/HT213986 - () https://support.apple.com/en-us/HT213986 - Vendor Advisory
CPE cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:14.0:*:*:*:*:*:*:*
cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.3
First Time Apple ipad Os
Webkitgtk webkitgtk
Wpewebkit wpe Webkit
Webkitgtk
Apple safari
Wpewebkit
Fedoraproject fedora
Apple iphone Os
Apple
Apple macos
Fedoraproject

21 Nov 2024, 08:23

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/03/26/1 - () http://www.openwall.com/lists/oss-security/2024/03/26/1 -
References () https://lists.fedoraproject.org/archives/list/[email protected]/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/ - () https://lists.fedoraproject.org/archives/list/[email protected]/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/ -
References () https://support.apple.com/en-us/HT213981 - () https://support.apple.com/en-us/HT213981 -
References () https://support.apple.com/en-us/HT213982 - () https://support.apple.com/en-us/HT213982 -
References () https://support.apple.com/en-us/HT213984 - () https://support.apple.com/en-us/HT213984 -
References () https://support.apple.com/en-us/HT213986 - () https://support.apple.com/en-us/HT213986 -

04 Nov 2024, 17:35

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 May 2024, 06:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/26/1 -
  • () https://lists.fedoraproject.org/archives/list/[email protected]/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/ -

Information

Published : 2024-02-21 07:15

Updated : 2024-12-09 17:31


NVD link : CVE-2023-42843

Mitre link : CVE-2023-42843

CVE.ORG link : CVE-2023-42843


JSON object : View

CWE
CWE-290

Authentication Bypass by Spoofing