Bug 2314705 (CVE-2024-40857) - CVE-2024-40857 webkitgtk: Processing maliciously crafted web content may lead to universal cross site scripting
Summary: CVE-2024-40857 webkitgtk: Processing maliciously crafted web content may lead...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2024-40857
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2314733 2314734
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-09-25 15:46 UTC by OSIDB Bzimport
Modified: 2024-09-25 22:32 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-09-25 22:32:25 UTC
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-09-25 15:46:52 UTC
Processing maliciously crafted web content may lead to universal cross site scripting. This issue was addressed through improved state management.

Comment 1 Robb Gatica 2024-09-25 19:57:25 UTC
https://webkitgtk.org/security/WSA-2024-0005.html

Comment 2 Michael Catanzaro 2024-09-25 22:32:25 UTC
This https://bugs.webkit.org/show_bug.cgi?id=CVE-2024-40857 is a WebArchive bug. We're not affected; it only affects Apple platforms and Windows.


Note You need to log in before you can comment on or make changes to this bug.