Unrated severityNVD Advisory· Published Oct 16, 2020· Updated Aug 4, 2024
CVE-2020-9915
CVE-2020-9915
Description
An access issue existed in Content Security Policy. This issue was addressed with improved access restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Affected products
73- osv-coords66 versionspkg:rpm/almalinux/dleyna-rendererpkg:rpm/almalinux/frei0r-develpkg:rpm/almalinux/frei0r-pluginspkg:rpm/almalinux/frei0r-plugins-opencvpkg:rpm/almalinux/gnome-remote-desktoppkg:rpm/almalinux/gtk-docpkg:rpm/almalinux/gvfspkg:rpm/almalinux/LibRaw-develpkg:rpm/almalinux/libsouppkg:rpm/almalinux/libsoup-develpkg:rpm/almalinux/mutter-develpkg:rpm/almalinux/nautiluspkg:rpm/almalinux/nautilus-develpkg:rpm/almalinux/PackageKitpkg:rpm/almalinux/PackageKit-command-not-foundpkg:rpm/almalinux/PackageKit-cronpkg:rpm/almalinux/PackageKit-glibpkg:rpm/almalinux/PackageKit-glib-develpkg:rpm/almalinux/PackageKit-gstreamer-pluginpkg:rpm/almalinux/PackageKit-gtk3-modulepkg:rpm/almalinux/pipewirepkg:rpm/almalinux/pipewire0.2-develpkg:rpm/almalinux/pipewire0.2-libspkg:rpm/almalinux/pipewire-develpkg:rpm/almalinux/pipewire-docpkg:rpm/almalinux/pipewire-libspkg:rpm/almalinux/pipewire-utilspkg:rpm/almalinux/potracepkg:rpm/almalinux/pygobject3-develpkg:rpm/almalinux/python3-gobjectpkg:rpm/almalinux/python3-gobject-basepkg:rpm/almalinux/trackerpkg:rpm/almalinux/tracker-develpkg:rpm/almalinux/vte291pkg:rpm/almalinux/vte291-develpkg:rpm/almalinux/vte-profilepkg:rpm/almalinux/webrtc-audio-processingpkg:rpm/almalinux/xdg-desktop-portal-gtkpkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/webkit2gtk3&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/webkit2gtk3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 0.6.0-3.el8+ 65 more
- (no CPE)range: < 0.6.0-3.el8
- (no CPE)range: < 1.6.1-7.el8
- (no CPE)range: < 1.6.1-7.el8
- (no CPE)range: < 1.6.1-7.el8
- (no CPE)range: < 0.1.8-3.el8
- (no CPE)range: < 1.28-2.el8
- (no CPE)range: < 1.36.2-10.el8
- (no CPE)range: < 0.19.5-2.el8
- (no CPE)range: < 2.62.3-2.el8
- (no CPE)range: < 2.62.3-2.el8
- (no CPE)range: < 3.32.2-48.el8
- (no CPE)range: < 3.28.1-14.el8
- (no CPE)range: < 3.28.1-14.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 1.1.12-6.el8
- (no CPE)range: < 0.3.6-1.el8
- (no CPE)range: < 0.2.7-6.el8
- (no CPE)range: < 0.2.7-6.el8
- (no CPE)range: < 0.3.6-1.el8
- (no CPE)range: < 0.3.6-1.el8
- (no CPE)range: < 0.3.6-1.el8
- (no CPE)range: < 0.3.6-1.el8
- (no CPE)range: < 1.15-3.el8
- (no CPE)range: < 3.28.3-2.el8
- (no CPE)range: < 3.28.3-2.el8
- (no CPE)range: < 3.28.3-2.el8
- (no CPE)range: < 2.1.5-2.el8
- (no CPE)range: < 2.1.5-2.el8
- (no CPE)range: < 0.52.4-2.el8
- (no CPE)range: < 0.52.4-2.el8
- (no CPE)range: < 0.52.4-2.el8
- (no CPE)range: < 0.3-9.el8
- (no CPE)range: < 1.6.0-1.el8
- (no CPE)range: < 2.28.4-lp151.2.24.3
- (no CPE)range: < 2.28.4-lp152.2.4.3
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-3.60.1
- (no CPE)range: < 2.28.4-3.60.1
- (no CPE)range: < 2.28.4-3.60.1
- (no CPE)range: < 2.28.4-3.6.1
- (no CPE)range: < 2.28.4-3.60.1
- (no CPE)range: < 2.28.4-3.6.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-3.60.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-3.60.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- (no CPE)range: < 2.28.4-2.59.1
- Range: unspecified
- Range: unspecified
- Range: unspecified
- Apple/iCloud for Windowsv5Range: unspecified
- Apple/iCloud for Windows (Legacy)v5Range: unspecified
- Range: unspecified
- Apple/iTunes for Windowsv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- support.apple.com/HT211288mitrex_refsource_MISC
- support.apple.com/HT211290mitrex_refsource_MISC
- support.apple.com/HT211291mitrex_refsource_MISC
- support.apple.com/HT211292mitrex_refsource_MISC
- support.apple.com/HT211293mitrex_refsource_MISC
- support.apple.com/HT211294mitrex_refsource_MISC
- support.apple.com/HT211295mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.