Cross-site scripting - CVE-2019-8690

 

Cross-site scripting - CVE-2019-8690

Published: December 18, 2019 / Updated: August 4, 2020


Vulnerability identifier: #VU33362
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2019-8690
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.


Affected software

webkit2gtk (Alpine package)
libjavascriptcoregtk-4_0-18
libjavascriptcoregtk-4_0-18-debuginfo
libwebkit2gtk-4_0-37
libwebkit2gtk-4_0-37-debuginfo
typelib-1_0-JavaScriptCore-4_0
typelib-1_0-WebKit2-4_0
typelib-1_0-WebKit2WebExtension-4_0
webkit2gtk-4_0-injected-bundles
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk3-debugsource
libwebkit2gtk3-lang
webkit2gtk3-devel
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Opensuse

How to mitigate CVE-2019-8690

Install update from vendor's website.

webkit2gtk (Alpine package) - update to 2.26.2-r0
libjavascriptcoregtk-4_0-18 - update to 2.34.3-2.82.1
libjavascriptcoregtk-4_0-18-debuginfo - update to 2.34.3-2.82.1
libwebkit2gtk-4_0-37 - update to 2.34.3-2.82.1
libwebkit2gtk-4_0-37-debuginfo - update to 2.34.3-2.82.1
typelib-1_0-JavaScriptCore-4_0 - update to 2.34.3-2.82.1
typelib-1_0-WebKit2-4_0 - update to 2.34.3-2.82.1
typelib-1_0-WebKit2WebExtension-4_0 - update to 2.34.3-2.82.1
webkit2gtk-4_0-injected-bundles - update to 2.34.3-2.82.1
webkit2gtk-4_0-injected-bundles-debuginfo - update to 2.34.3-2.82.1
webkit2gtk3-debugsource - update to 2.34.3-2.82.1
libwebkit2gtk3-lang - update to 2.34.3-2.82.1
webkit2gtk3-devel - update to 2.34.3-2.82.1

External References

Related Security Bulletins