CVE-2021-30862

A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:itunes_u:*:*:*:*:*:*:*:*

History

01 Nov 2021, 13:00

Type Values Removed Values Added
CPE cpe:2.3:a:apple:itunes_u:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CWE CWE-20
References (MISC) https://support.apple.com/en-us/HT212809 - (MISC) https://support.apple.com/en-us/HT212809 - Vendor Advisory

28 Oct 2021, 19:15

Type Values Removed Values Added
Summary ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by the CVE program. Notes: none. A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
References
  • (MISC) https://support.apple.com/en-us/HT212809 -

24 Aug 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-24 19:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-30862

Mitre link : CVE-2021-30862

CVE.ORG link : CVE-2021-30862


JSON object : View

Products Affected

apple

  • itunes_u
CWE
CWE-20

Improper Input Validation