CVE-2021-30890

MEDIUM

iPadOS < 15.1 - Universal Cross-Site Scripting

Title source: llm
STIX 2.1

Description

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.

References (9)

Core 9
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212869
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212867
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212874
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212876
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-5030
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-5031
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/12/20/6

Scores

CVSS v3 6.1
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (9)
apple/ipados < 15.1
apple/iphone_os < 15.1
apple/macos < 12.0.1
apple/tvos < 15.1
apple/watchos < 8.1
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
Published Aug 24, 2021
Tracked Since Feb 18, 2026