DEBIAN-CVE-2021-1801

Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 02 Apr 2021, 19:15
Last modified:19 Nov 2025, 01:01

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Apr 2021, 19:15
Published
Vulnerability first disclosed
19 Nov 2025, 01:01
Last Modified
Vulnerability information updated

Description

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Maliciously crafted web content may violate iframe sandboxing policy.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Systems

  • debianwebkit2gtk

    < 2.30.6-1 | < 2.30.6-1 | < 2.30.6-1 | < 2.30.6-1

  • debianwpewebkit

    < 2.30.6-1 | < 2.30.6-1 | < 2.30.6-1 | < 2.30.6-1

References (1)