First published: Mon Dec 14 2020(Updated: )
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.
Credit: product-security@apple.com Rajpal Arora @whacktohack Rohan Sharma (r0hanSH)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Server | <5.11 | 5.11 |
Apple macOS Server | <5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-9995.
The severity rating of CVE-2020-9995 is 6.1 (Medium).
macOS Server versions up to and including 5.11 are affected by CVE-2020-9995.
Processing a maliciously crafted URL may lead to an open redirect or cross-site scripting.
CVE-2020-9995 is fixed in macOS Server 5.11, so updating to this version will resolve the vulnerability.