First published: Thu Sep 14 2023(Updated: )
Versions affected: WebKitGTK and WPE WebKit before 2.40.1. Credit to Gertjan Franken of imec-DistriNet, KU Leuven. Impact: Content Security Policy to block domains with wildcards may fail. Description: A logic issue was addressed with improved validation.
Affected Software | Affected Version | How to fix |
---|---|---|
WebKitGTK | <2.40.1 | |
WebKit | <2.40.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2238944 is classified as a moderate severity vulnerability due to its impact on Content Security Policy functionality.
To resolve REDHAT-BUG-2238944, update WebKitGTK and WPE WebKit to version 2.40.1 or later.
Versions of WebKitGTK and WPE WebKit prior to 2.40.1 are affected by REDHAT-BUG-2238944.
The impact of REDHAT-BUG-2238944 is that Content Security Policy may fail to properly block domains with wildcards.
REDHAT-BUG-2238944 was reported by Gertjan Franken from imec-DistriNet, KU Leuven.