Information disclosure in WebKitGTK+ - CVE-2018-11712
Published: August 22, 2018 / Updated: August 23, 2018
WebKitGTK+
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The vulnerability exists in WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit due to improper TLS certificate verification for WebSocket connections. A remote unauthenticated attacker can gain access to important data.