ID

VAR-202104-0753


CVE

CVE-2021-1879


TITLE

plural  Apple  Cross-site scripting vulnerability in the product

Trust: 0.8

sources: JVNDB: JVNDB-2021-013399

DESCRIPTION

This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited.. iOS , iPadOS , watchOS Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. Apple iOS, iPadOS and watchOS universal XSS exploited in the wild. Versions of iPhone, iPad, iPod, Apple Watch are affected. Alternatively, on your watch, select "My Watch > General > About". -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2021-03-26-1 iOS 14.4.2 and iPadOS 14.4.2 iOS 14.4.2 and iPadOS 14.4.2 addresses the following issue. Information about the security content is also available at https://support.apple.com/HT212256. WebKit Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: Processing maliciously crafted web content may lead to universal cross site scripting. CVE-2021-1879: Clement Lecigne of Google Threat Analysis Group and Billy Leonard of Google Threat Analysis Group Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "iOS 14.4.2 and iPadOS 14.4.2". Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAmBeODIACgkQZcsbuWJ6 jjDsnw//asz2IB0wWiWimjgw1aJroh2wVuw8DITpTWAt3mJS223D8p+fLDf2aqx8 UO7Oxjzdq03oJbByaoER624K2hmw915YXdFsfDBLN4TaSrQaUAst0SzzTMSzdA3t V1Uot8MaXpIidP+eYrnWWSFllQfqYIB9f/RYiZ07CKqjA8G95S821XMfjQ9CJkzW 9oQW92KUshjxR6rNN61+Tkvyh9Z9rT6a6D4OKlX4RoEcSyXHNbJmCFC2fx8Tw4xm BnP7vXyYLMOhBLiNX+L2q2ph96E57hV77IsSWNKkdtD83cygqtt+4u/W3wdnee+U yLGHRXe36vD1WvInb2b1EoDOWqC/CVCWf9gzES5HE58VN1CGfXiH4+kykEdO5HqN cJGZTFxibIReDrtpxhhW0zS6JUwFMXgVLlLPlLBqCFf2TGDWKe6XX0v7D0PgNqZX 94O1/DVYCadiUvSMnv6lkTertH+UJJ6MNu+nyTjtkX183JLOUsMlZyLxZ6mpM91y lF7NOIh9Dy5XgzU1sJhDqtMqhyvk7jxGIm6DES2xf5+YSHFqujGVPeHXUFq9AVbx aK/YYyT++Nf1tfyE1CsH6+M7IcsJe9wVmsKljZ5MXX7W4tBj9l3NwQnPAbejy+vb /msbc8BVIDBgZYgj2vThRy4IIYjn5on30BzRhTfB08H4bGkSbII= =0iO5 -----END PGP SIGNATURE-----

Trust: 2.07

sources: NVD: CVE-2021-1879 // JVNDB: JVNDB-2021-013399 // VULHUB: VHN-376539 // VULMON: CVE-2021-1879 // PACKETSTORM: 162002 // PACKETSTORM: 162003 // PACKETSTORM: 161999

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:gteversion:13.0

Trust: 1.0

vendor:applemodel:iphone osscope:ltversion:14.4.2

Trust: 1.0

vendor:applemodel:ipadosscope:ltversion:14.4.2

Trust: 1.0

vendor:applemodel:watchosscope:ltversion:7.3.3

Trust: 1.0

vendor:applemodel:iphone osscope:ltversion:12.5.2

Trust: 1.0

vendor:アップルmodel:ipadosscope: - version: -

Trust: 0.8

vendor:アップルmodel:watchosscope: - version: -

Trust: 0.8

vendor:アップルmodel:iosscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-013399 // NVD: CVE-2021-1879

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-1879
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-1879
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202103-1573
value: MEDIUM

Trust: 0.6

VULHUB: VHN-376539
value: MEDIUM

Trust: 0.1

VULMON: CVE-2021-1879
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-1879
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-376539
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-1879
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 1.0

NVD: CVE-2021-1879
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-376539 // VULMON: CVE-2021-1879 // JVNDB: JVNDB-2021-013399 // CNNVD: CNNVD-202103-1573 // NVD: CVE-2021-1879

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.1

problemtype:Cross-site scripting (CWE-79) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-376539 // JVNDB: JVNDB-2021-013399 // NVD: CVE-2021-1879

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202103-1573

TYPE

xss

Trust: 0.9

sources: PACKETSTORM: 162002 // PACKETSTORM: 162003 // PACKETSTORM: 161999 // CNNVD: CNNVD-202103-1573

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-376539

PATCH

title:HT212257 Apple  Security updateurl:https://support.apple.com/en-us/HT212256

Trust: 0.8

title:Apple iOS WebKit Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=147287

Trust: 0.6

title:The Registerurl:https://www.theregister.co.uk/2021/03/29/in_brief_security/

Trust: 0.2

title:PS4CVE20211879url:https://github.com/Nazky/PS4CVE20211879

Trust: 0.1

title:NIST Bulk CVE Lookup by Jay Chen Sample outputurl:https://github.com/jaychen2/NIST-BULK-CVE-Lookup

Trust: 0.1

title:Known Exploited Vulnerabilities Detectorurl:https://github.com/Ostorlab/KEV

Trust: 0.1

title: - url:https://www.welivesecurity.com/2021/03/29/apple-rushes-patch-zero-day-flaw-ios-ipados/

Trust: 0.1

sources: VULMON: CVE-2021-1879 // JVNDB: JVNDB-2021-013399 // CNNVD: CNNVD-202103-1573

EXTERNAL IDS

db:NVDid:CVE-2021-1879

Trust: 3.7

db:PACKETSTORMid:162002

Trust: 0.8

db:JVNDBid:JVNDB-2021-013399

Trust: 0.8

db:CNNVDid:CNNVD-202103-1573

Trust: 0.7

db:AUSCERTid:ESB-2021.1067

Trust: 0.6

db:PACKETSTORMid:162003

Trust: 0.2

db:PACKETSTORMid:161999

Trust: 0.2

db:VULHUBid:VHN-376539

Trust: 0.1

db:VULMONid:CVE-2021-1879

Trust: 0.1

sources: VULHUB: VHN-376539 // VULMON: CVE-2021-1879 // JVNDB: JVNDB-2021-013399 // PACKETSTORM: 162002 // PACKETSTORM: 162003 // PACKETSTORM: 161999 // CNNVD: CNNVD-202103-1573 // NVD: CVE-2021-1879

REFERENCES

url:https://support.apple.com/en-us/ht212256

Trust: 1.8

url:https://support.apple.com/en-us/ht212257

Trust: 1.8

url:https://support.apple.com/en-us/ht212258

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-1879

Trust: 1.7

url:https://cisa.gov/known-exploited-vulnerabilities-catalog

Trust: 0.8

url:https://vigilance.fr/vulnerability/apple-ios-cross-site-scripting-via-webkit-34954

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.1067

Trust: 0.6

url:https://packetstormsecurity.com/files/162002/apple-security-advisory-2021-03-26-2.html

Trust: 0.6

url:https://support.apple.com/kb/ht201222

Trust: 0.3

url:https://www.apple.com/support/security/pgp/

Trust: 0.3

url:https://www.apple.com/itunes/

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://github.com/nazky/ps4cve20211879

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://support.apple.com/tr-tr/ht212257

Trust: 0.1

url:https://support.apple.com/ht212257.

Trust: 0.1

url:https://support.apple.com/kb/ht204641

Trust: 0.1

url:https://support.apple.com/ht212258.

Trust: 0.1

url:https://support.apple.com/ht212256.

Trust: 0.1

sources: VULHUB: VHN-376539 // VULMON: CVE-2021-1879 // JVNDB: JVNDB-2021-013399 // PACKETSTORM: 162002 // PACKETSTORM: 162003 // PACKETSTORM: 161999 // CNNVD: CNNVD-202103-1573 // NVD: CVE-2021-1879

CREDITS

Apple

Trust: 0.9

sources: PACKETSTORM: 162002 // PACKETSTORM: 162003 // PACKETSTORM: 161999 // CNNVD: CNNVD-202103-1573

SOURCES

db:VULHUBid:VHN-376539
db:VULMONid:CVE-2021-1879
db:JVNDBid:JVNDB-2021-013399
db:PACKETSTORMid:162002
db:PACKETSTORMid:162003
db:PACKETSTORMid:161999
db:CNNVDid:CNNVD-202103-1573
db:NVDid:CVE-2021-1879

LAST UPDATE DATE

2024-08-14T14:50:17.319000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-376539date:2023-01-09T00:00:00
db:VULMONid:CVE-2021-1879date:2023-01-09T00:00:00
db:JVNDBid:JVNDB-2021-013399date:2024-05-31T06:10:00
db:CNNVDid:CNNVD-202103-1573date:2021-04-13T00:00:00
db:NVDid:CVE-2021-1879date:2024-05-16T01:00:02.197

SOURCES RELEASE DATE

db:VULHUBid:VHN-376539date:2021-04-02T00:00:00
db:VULMONid:CVE-2021-1879date:2021-04-02T00:00:00
db:JVNDBid:JVNDB-2021-013399date:2022-09-08T00:00:00
db:PACKETSTORMid:162002date:2021-03-29T14:36:54
db:PACKETSTORMid:162003date:2021-03-29T14:37:43
db:PACKETSTORMid:161999date:2021-03-29T14:24:26
db:CNNVDid:CNNVD-202103-1573date:2021-03-29T00:00:00
db:NVDid:CVE-2021-1879date:2021-04-02T19:15:20.770