CVE-2010-1760

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r50173:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r56187:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r56188:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r56379:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-08-19 22:00

Updated : 2011-03-18 02:49


NVD link : CVE-2010-1760

Mitre link : CVE-2010-1760

CVE.ORG link : CVE-2010-1760


JSON object : View

Products Affected

apple

  • webkit
CWE
CWE-255

Credentials Management Errors