CVE-2024-23280

EUVD-2024-20799
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
applesafari
𝑥
< 17.4
appleipad_os
𝑥
< 17.4
appleiphone_os
𝑥
< 17.4
applemacos
14.0 ≤
𝑥
< 14.4
appletvos
𝑥
< 17.4
applewatchos
𝑥
< 10.4
webkitgtkwebkitgtk
𝑥
< 2.44.0
wpewebkitwpe_webkit
𝑥
< 2.44.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
appletvos
𝑥
< 17.4
ADP
appleios
𝑥
< 17.4
ADP
appleipados
𝑥
< 17.4
ADP
applesafari
𝑥
< 17.4
ADP
applemacos
𝑥
< 17.4
ADP
applewatchos
𝑥
< 17.4
ADP
Debian logo
Debian Releases
Debian Product
Codename
webkit2gtk
bookworm
2.48.5-1~deb12u1
ignored
bookworm (security)
2.50.4-1~deb12u1
fixed
bullseye
2.44.2-1~deb11u1
ignored
bullseye (security)
2.50.4-1~deb11u1
fixed
forky
2.50.4-1
fixed
sid
2.50.4-1
fixed
trixie
2.50.1-1~deb13u1
fixed
trixie (security)
2.50.4-1~deb13u1
fixed
wpewebkit
bookworm
ignored
bullseye
ignored
bullseye (security)
vulnerable
forky
2.50.4-1
fixed
sid
2.50.4-1
fixed
trixie
2.48.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
webkitgtk
bionic
ignored
focal
dne
jammy
dne
mantic
dne
noble
dne
xenial
ignored
webkit2gtk
bionic
ignored
focal
ignored
jammy
Fixed 2.44.0-0ubuntu0.22.04.1
released
mantic
Fixed 2.44.0-0ubuntu0.23.10.1
released
noble
not-affected
xenial
ignored
qtwebkit-source
bionic
ignored
focal
dne
jammy
dne
mantic
dne
noble
dne
xenial
ignored
wpewebkit
focal
ignored
jammy
ignored
mantic
dne
noble
dne
qtwebkit-opensource-src
bionic
ignored
focal
ignored
jammy
ignored
mantic
ignored
noble
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libjavascriptcoregtk-4_0-18
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
libjavascriptcoregtk-4_1-0
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
libjavascriptcoregtk-6_0-1
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
libwebkit2gtk-4_0-37
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
libwebkit2gtk-4_1-0
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
libwebkit2gtk3-lang
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
libwebkitgtk-6_0-4
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-JavaScriptCore-4_0
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-JavaScriptCore-4_1
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-JavaScriptCore-6_0
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-WebKit-6_0
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-WebKit2-4_0
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-WebKit2-4_1
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-WebKit2WebExtension-4_0
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-WebKit2WebExtension-4_1
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
typelib-1_0-WebKitWebProcessExtension-6_0
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
webkit2gtk-4_0-injected-bundles
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 12 SP5
2.44.2-4.7.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 12 SP3
2.44.2-4.7.1
fixed
suse enterprise server 12 SP5
2.44.2-4.7.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
webkit2gtk-4_1-injected-bundles
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
webkit2gtk3-devel
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP2
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP3
2.44.0-150200.107.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
webkit2gtk3-soup2-devel
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
webkit2gtk4-devel
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
webkitgtk-6_0-injected-bundles
suse enterprise desktop 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise desktop 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise desktop 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise sap 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise sap 15 SP7
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP4
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP5
2.44.0-150400.4.78.1
fixed
suse enterprise server 15 SP6
2.44.2-150600.12.3.1
fixed
suse enterprise server 15 SP7
2.44.2-150600.12.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
webkit2gtk3
RHEL 8
0:2.46.3-2.el8_10
fixed
RHEL 9
0:2.46.1-2.el9_4
fixed
webkit2gtk3-devel
RHEL 8
0:2.46.3-2.el8_10
fixed
RHEL 9
0:2.46.1-2.el9_4
fixed
webkit2gtk3-jsc
RHEL 8
0:2.46.3-2.el8_10
fixed
RHEL 9
0:2.46.1-2.el9_4
fixed
webkit2gtk3-jsc-devel
RHEL 8
0:2.46.3-2.el8_10
fixed
RHEL 9
0:2.46.1-2.el9_4
fixed