loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple webkit |
||
apple webkit r50173 |
||
apple webkit r56187 |
||
apple webkit r56188 |
||
apple webkit r56379 |