yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-23280
Component Overview
Vulnerability Overview
Name
CVE-2024-23280
Source
NVD (
link
)
Debian (
link
)
Description
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
CWEs
CWE-74
Published Date
Mar 8, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://seclists.org/fulldisclosure/2024/Mar/20
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/21
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/24
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/25
Mailing List
http://www.openwall.com/lists/oss-security/2024/03/26/1
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AO4BNNL5X2LQBJ6WX7VT4SGMA6R7DUU5/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI/
Mailing List
https://support.apple.com/en-us/HT214081
Vendor Advisory
https://support.apple.com/en-us/HT214084
Vendor Advisory
https://support.apple.com/en-us/HT214086
Vendor Advisory
https://support.apple.com/en-us/HT214088
Vendor Advisory
https://support.apple.com/en-us/HT214089
Vendor Advisory
Analysis
#
Affected Component
Analysis
webkitgtk
Exploitable
Vulnerability Ratings
#
6.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
webkitgtk
buildroot
2025.02.x
2.52.3
Not Affected
webkitgtk
buildroot
master
2.52.3
Not Affected
webkitgtk
yocto
master
2.50.6
Not Affected
webkitgtk
yocto
scarthgap
2.44.4
Not Affected