Beveiligingsadvies

CVE-2015-3750

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2015-08-16 23:00:00
Laatst bijgewerkt 2024-08-06 05:56:14
Toegewezen door apple
CVSS-score geen score
Status PUBLISHED

Beschrijving

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.