Univeral cross-site scripting in WebKitGTK+ and WPE WebKit - CVE-2020-9925
Published: August 2, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of arbitrary website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
WPE WebKit
Gentoo Linux
Debian Linux
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Opensuse
Ubuntu
Fedora
Service Telemetry Framework
webkit2gtk (Alpine package)
gnome-remote-desktop (Red Hat package)
pipewire0.2 (Red Hat package)
pipewire (Red Hat package)
webrtc-audio-processing (Red Hat package)
dleyna-renderer (Red Hat package)
LibRaw (Red Hat package)
vte291 (Red Hat package)
PackageKit (Red Hat package)
xdg-desktop-portal-gtk (Red Hat package)
xdg-desktop-portal (Red Hat package)
frei0r-plugins (Red Hat package)
potrace (Red Hat package)
gtk-doc (Red Hat package)
gvfs (Red Hat package)
tracker (Red Hat package)
libjavascriptcoregtk-4.0-18 (Ubuntu package)
libwebkit2gtk-4.0-37 (Ubuntu package)
webkit2gtk3 (Red Hat package)
webkit2gtk (Debian package)
webkit2gtk3
webkitgtk4 (Red Hat package)
libsoup (Red Hat package)
gtk3 (Red Hat package)
gnome-photos (Red Hat package)
gnome-session (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
pygobject3 (Red Hat package)
gnome-terminal (Red Hat package)
gdm (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2020-9925
WPE WebKit - update to 2.28.4
webkit2gtk (Alpine package) - update to 2.28.4-r0
Quay - update to 3.3.3
gnome-remote-desktop (Red Hat package) - update to 0.1.8-3.el8
pipewire0.2 (Red Hat package) - update to 0.2.7-6.el8
pipewire (Red Hat package) - update to 0.3.6-1.el8
webrtc-audio-processing (Red Hat package) - update to 0.3-9.el8
dleyna-renderer (Red Hat package) - update to 0.6.0-3.el8
LibRaw (Red Hat package) - update to 0.19.5-2.el8
vte291 (Red Hat package) - update to 0.52.4-2.el8
PackageKit (Red Hat package) - update to 1.1.12-6.el8
xdg-desktop-portal-gtk (Red Hat package) - update to 1.6.0-1.el8
xdg-desktop-portal (Red Hat package) - update to 1.6.0-2.el8
frei0r-plugins (Red Hat package) - update to 1.6.1-7.el8
potrace (Red Hat package) - update to 1.15-3.el8
gtk-doc (Red Hat package) - update to 1.28-2.el8
gvfs (Red Hat package) - update to 1.36.2-10.el8
tracker (Red Hat package) - update to 2.1.5-2.el8
libjavascriptcoregtk-4.0-18 (Ubuntu package) - addressed in versions 2.28.4-0ubuntu0.18.04.1, 2.28.4-0ubuntu0.20.04.1
libwebkit2gtk-4.0-37 (Ubuntu package) - addressed in versions 2.28.4-0ubuntu0.18.04.1, 2.28.4-0ubuntu0.20.04.1
webkit2gtk3 (Red Hat package) - update to 2.28.4-1.el8
webkit2gtk (Debian package) - update to 2.28.4-1~deb10u1
webkit2gtk3 - addressed in versions 2.28.4-3.fc31, 2.28.4-3.fc32
webkitgtk4 (Red Hat package) - update to 2.48.3-2.el7_9
libsoup (Red Hat package) - update to 2.62.3-2.el8
gtk3 (Red Hat package) - update to 3.22.30-6.el8
gnome-photos (Red Hat package) - update to 3.28.1-3.el8
gnome-session (Red Hat package) - update to 3.28.1-10.el8
nautilus (Red Hat package) - update to 3.28.1-14.el8
gnome-control-center (Red Hat package) - update to 3.28.2-22.el8
pygobject3 (Red Hat package) - update to 3.28.3-2.el8
gnome-terminal (Red Hat package) - update to 3.28.3-2.el8
gdm (Red Hat package) - update to 3.28.3-34.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-5.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-11.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-11.el8
gnome-shell (Red Hat package) - update to 3.32.2-20.el8
mutter (Red Hat package) - update to 3.32.2-48.el8
External References
Related Security Bulletins
- Multiple vulnerabilities in WebKitGTK+ and WPE WebKit
- Gentoo update for WebKitGTK+
- OpenSUSE Linux update for webkit2gtk3
- Univeral cross-site scripting in webkit2gtk (Alpine package)
- OpenSUSE Linux update for webkit2gtk3
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Debian update for webkit2gtk
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Red Hat Enterprise Linux 8 update for GNOME
- Ubuntu update for webkit2gtk
- Fedora 32 update for webkit2gtk3
- Fedora 31 update for webkit2gtk3
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for webkitgtk4