First published: Mon Jul 14 2008(Updated: )
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Xcode | =2.2.1 | |
Apple Xcode | =2.4 | |
Apple Xcode | =2.1 | |
Apple Xcode | =1.5 | |
Apple Xcode | =2.3 | |
Apple Xcode | =2.2 | |
Apple Xcode | =2.0 | |
Apple Xcode | =1.0 | |
Apple Xcode | =2.4.1 | |
Apple Xcode | <=3.0 | |
Apple Xcode | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2318 is classified as a moderate severity vulnerability that can lead to information leakage.
To mitigate CVE-2008-2318, upgrade to a version of Apple Xcode tools newer than 3.0.
CVE-2008-2318 allows remote attackers to potentially obtain sensitive session information via HTTP requests.
CVE-2008-2318 affects Apple Xcode tools versions 1.0 up to and including 3.0.
CVE-2008-2318 could be considered widespread due to its presence in multiple versions of Apple Xcode tools utilized by developers.