CVE-2019-8771
6.1
MEDIUM
CVSS 3.1
EPSS 0.24%
Description
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.
How to fix CVE-2019-8771
To remediate CVE-2019-8771, upgrade the affected package to a fixed version below.
- Debian/webkit2gtk—upgrade to 2.26.0-1 or later
Is CVE-2019-8771 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.26.0-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |