Improper authorization control for web services In webkitgtk3
Description
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package |
|---|---|
rpm rhel7 | |
rpm rhel6 | |
rpm rhel8 | |
rpm rhel9 | |
rpm rhel7 |
Aliases
1. 2. 3.