HIGH
webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code
Published Sep 26, 2023
8.8
HIGHCVSS 3.1
EPSS 1.08%
Description
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<17
- Version
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
webkitgtk4-0:2.48.3-2.el7_9
Fixed · RHSA-2025:10364
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.40.5-1.el8
Fixed · RHSA-2023:7055
Red Hat Enterprise Linux 9
webkit2gtk3-0:2.40.5-1.el9
Fixed · RHSA-2023:6535
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | webkitgtk4-0:2.48.3-2.el7_9 | Fixed | RHSA-2025:10364 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.40.5-1.el8 | Fixed | RHSA-2023:7055 |
| Red Hat Enterprise Linux 9 | webkit2gtk3-0:2.40.5-1.el9 | Fixed | RHSA-2023:6535 |
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://seclists.org/fulldisclosure/2023/Oct/2 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/09/28/3 Mailing List
- https://access.redhat.com/security/cve/CVE-2023-40451 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2241409 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2023-40451
- https://security.gentoo.org/glsa/202401-33
- https://support.apple.com/en-us/HT213941 Vendor Advisory
- https://webkitgtk.org/security/WSA-2023-0009.html
- https://www.cve.org/CVERecord?id=CVE-2023-40451
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2023/Oct/2 | Mailing ListThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2023/09/28/3 | Mailing List | |
| https://access.redhat.com/security/cve/CVE-2023-40451 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2241409 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-40451 | ||
| https://security.gentoo.org/glsa/202401-33 | ||
| https://support.apple.com/en-us/HT213941 | Vendor Advisory | |
| https://webkitgtk.org/security/WSA-2023-0009.html | ||
| https://www.cve.org/CVERecord?id=CVE-2023-40451 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Sep 26, 2023
Updated Feb 13, 2025
Reserved Aug 14, 2023
Link CVE-2023-40451
CISA Vulnrichment
Updated Feb 1, 2024