CVE-2021-30823 The advisory has been revoked - it doesn't affect any version of package webkitgtk4-doc  (opens in a new tab)


Threat Intelligence

EPSS
2.06% (80th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-WEBKITGTK4DOC-2322469
  • published21 Dec 2021
  • disclosed20 Dec 2021

Introduced: 20 Dec 2021

CVE-2021-30823  (opens in a new tab)

Amendment

The Red Hat security team deemed this advisory irrelevant for RHEL:7.

NVD Description

Note: Versions mentioned in the description apply only to the upstream webkitgtk4-doc package and not the webkitgtk4-doc package as distributed by RHEL.

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadOS 14.8, tvOS 15, Safari 15, watchOS 8. An attacker in a privileged network position may be able to bypass HSTS.