First published: Thu Mar 29 2018(Updated: )
An issue was discovered in certain Apple products. Safari before 11.1 is affected. The issue involves the "WebKit" component. A Safari cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: Anton Lopanitsyn WallarmLinus Särud DetectifyYuji Tounai NTT Communications Corporation product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <11.1 | 11.1 |
Apple Safari | <11.1 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Webkitgtk Webkitgtk\+ | <2.20.4 | |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.3-1~deb11u1 2.44.2-1~deb12u1 2.46.0-2~deb12u1 2.46.0-2 2.46.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4133 is a cross-site scripting (XSS) vulnerability in Safari before version 11.1.
Safari versions up to and excluding 11.1 are affected.
Remote attackers can exploit this vulnerability by injecting arbitrary web script or HTML via a crafted URL.
CVE-2018-4133 has a severity rating of 6.1 (Medium).
Yes, you can find references for CVE-2018-4133 at the following links: http://www.securityfocus.com/bid/103580, http://www.securitytracker.com/id/1040606, https://security.gentoo.org/glsa/201808-04