VDB
CVE-2008-2318
CVE-2008-2318
PUBLISHED
CVSS 5 MEDIUM
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.
EPSS 1.46% · 71.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.46%
71.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | xcode_tools | 0, 1.0, 2.4.1 |
| apple | xcode | 2.2, 1.5 |
| n/a | n/a | n/a |
Timeline
- Jul 14, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- apple-xcode-webobjects-info-disclosure(43735) vdb
- 1020473 vdb
- 30191 vdb
- ADV-2008-2093 vdb
- APPLE-SA-2008-07-11 vendor-advisory
- http://support.apple.com/kb/HT2352 url
- 31060 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-2318 advisory