Description
The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/79707
Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-03/msg00054.html
Vendor Advisory x_refsource_confirm
https://support.apple.com/HT205265
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033688
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2015/Sep/msg00007.html
Scores
EPSS
0.0078
EPSS Percentile
73.9%
Details
CWE
CWE-20
Status
published
Products (2)
apple/safari
< 8.0.8
opensuse/leap
42.1
Published
Oct 09, 2015
Tracked Since
Feb 18, 2026