Universal cross-site scripting in WebKitGTK+ and WPE WebKit - CVE-2024-40785

 

Universal cross-site scripting in WebKitGTK+ and WPE WebKit - CVE-2024-40785

Published: July 30, 2024 / Updated: August 19, 2024


Vulnerability identifier: #VU94881
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-40785
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

WebKitGTK+
WPE WebKit
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
visionOS
SUSE Enterprise Storage
watchOS
SUSE Linux Enterprise Workstation Extension 12
macOS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
iPadOS
Apple iOS
tvOS
Apple Safari
webkit2gtk (Debian package)
libjavascriptcoregtk-4_0-18-debuginfo
libjavascriptcoregtk-4_0-18-32bit
libwebkit2gtk3-lang
libjavascriptcoregtk-4_0-18
libwebkit2gtk-4_0-37-debuginfo
typelib-1_0-JavaScriptCore-4_0
libwebkit2gtk-4_0-37
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk-4_0-injected-bundles
typelib-1_0-WebKit2-4_0
webkit2gtk3-devel
webkit2gtk3-debugsource
typelib-1_0-WebKit2WebExtension-4_0

How to mitigate CVE-2024-40785

Install update from vendor's website.

WebKitGTK+ - update to 2.44.3
WPE WebKit - update to 2.44.3
visionOS - update to 1.3
watchOS - update to 10.6
macOS - update to 14.6 23G80
iPadOS - addressed in versions 16.7.9 20H348, 17.6 21G80
Apple iOS - addressed in versions 16.7.9 20H348, 17.6 21G80
tvOS - update to 17.6
Apple Safari - update to 17.6
webkit2gtk (Debian package) - update to 2.44.3-1~deb12u1
libjavascriptcoregtk-4_0-18-debuginfo - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libjavascriptcoregtk-4_0-18-32bit - update to 2.44.3-4.12.1
libwebkit2gtk3-lang - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libjavascriptcoregtk-4_0-18 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libwebkit2gtk-4_0-37-debuginfo - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
typelib-1_0-JavaScriptCore-4_0 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
libwebkit2gtk-4_0-37 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk-4_0-injected-bundles-debuginfo - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk-4_0-injected-bundles - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
typelib-1_0-WebKit2-4_0 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk3-devel - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
webkit2gtk3-debugsource - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1
typelib-1_0-WebKit2WebExtension-4_0 - addressed in versions 2.44.3-4.12.1, 2.44.3-150200.118.1

External References

Related Security Bulletins