First published: Wed Sep 12 2018(Updated: )
WebKit. A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation.
Credit: Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk Jun Kokatsu @shhnjk product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iCloud for Windows | <7.7 | 7.7 |
Apple iTunes for Windows | <12.9 | 12.9 |
Apple Safari | <12 | 12 |
Apple tvOS | <12 | 12 |
Apple iOS | <12 | 12 |
Apple Safari | <12 | |
Apple iPhone OS | <12.0 | |
Apple tvOS | <12 | |
Apple iCloud | <7.7 | |
Apple iTunes | <12.9 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-4345 is a cross-site scripting vulnerability that existed in Safari.
Versions prior to Safari 12 are affected by CVE-2018-4345.
iOS versions prior to 12, tvOS versions prior to 12, iTunes for Windows versions prior to 12.9, and iCloud for Windows versions prior to 7.7 are also affected by CVE-2018-4345.
The severity of CVE-2018-4345 is medium with a CVSS score of 6.1.
To fix CVE-2018-4345, update to the latest version of Safari (version 12 or later), iOS 12 or later, tvOS 12 or later, iTunes for Windows 12.9 or later, and iCloud for Windows 7.7 or later.