CVE-2019-8690: XSS
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.
Other sources
WebKit. A logic issue existed in the handling of document loads. This issue was addressed with improved state management.
WebKitGTK Security Advisory WSA-2019-0004 describes the following issue:
CVE-2019-8690
Processing maliciously crafted web content may lead to universal cross site scripting. A logic issue existed in the handling of document loads. This issue was addressed with improved state management.
Versions affected: WebKitGTK and WPE WebKit before 2.24.3.
— Red Hat
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8646
- CVE-2019-8647
- CVE-2019-8660
- CVE-2019-8702
- CVE-2018-16860
- CVE-2019-8668
- CVE-2019-13118
- CVE-2019-8698
- CVE-2019-8662
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-8661
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2019-8694
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8665
- CVE-2019-8699
- CVE-2019-8682
Frequently Asked Questions
What is CVE-2019-8690?
CVE-2019-8690 is a vulnerability in WebKit that existed in the handling of document loads.
How severe is CVE-2019-8690?
CVE-2019-8690 has a severity level of 6.1 out of 10.
Which software versions are affected by CVE-2019-8690?
The affected software versions include iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6.
How do I fix CVE-2019-8690?
To fix CVE-2019-8690, update your software to the fixed versions: iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, and iCloud for Windows 10.6.
What is the Common Weakness Enumeration (CWE) for CVE-2019-8690?
The CWE for CVE-2019-8690 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').