CVE-2019-8658: XSS
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
Other sources
WebKit. A logic issue was addressed with improved state management.
WebKitGTK Security Advisory WSA-2019-0004 describes the following issue:
CVE-2019-8658
Processing maliciously crafted web content may lead to universal cross site scripting. A logic issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8646
- CVE-2019-8647
- CVE-2019-8660
- CVE-2019-8702
- CVE-2018-16860
- CVE-2019-8668
- CVE-2019-13118
- CVE-2019-8698
- CVE-2019-8662
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-8661
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2019-8694
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8624
- CVE-2019-8633
- CVE-2019-8659
- CVE-2019-8665
- CVE-2019-8682
- CVE-2019-8699
Frequently Asked Questions
What is the vulnerability CVE-2019-8658?
CVE-2019-8658 is a logic issue in WebKit with improved state management.
What is the severity of CVE-2019-8658?
The severity of CVE-2019-8658 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2019-8658?
iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6 are affected by CVE-2019-8658.
How can I fix CVE-2019-8658?
To fix CVE-2019-8658, update to the fixed versions: iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, or iCloud for Windows 10.6.
What is the Common Weakness Enumeration (CWE) for CVE-2019-8658?
The CWE for CVE-2019-8658 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')