REDHAT-BUG-2241409: Medium severity webkit vulnerability
An attacker with JavaScript execution may be able to execute arbitrary code. This issue was addressed with improved iframe sandbox enforcement.
Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-40451
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2241409?
REDHAT-BUG-2241409 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-2241409?
To fix REDHAT-BUG-2241409, ensure that you update your Apple WebKit to the latest version where the iframe sandbox enforcement has been improved.
What causes the vulnerability REDHAT-BUG-2241409?
The vulnerability REDHAT-BUG-2241409 is caused by inadequate sandboxing of iframes, allowing an attacker with JavaScript execution to run arbitrary code.
Who is affected by REDHAT-BUG-2241409?
Users of Apple WebKit are affected by REDHAT-BUG-2241409 if they are using an outdated version of the software.
When was REDHAT-BUG-2241409 disclosed?
REDHAT-BUG-2241409 was disclosed in the 2023 security advisory for Apple WebKit.