CVE-2019-11070

Severity CVSS v4.0:
Pending analysis
Type:
CWE-19 Data Handling
Publication date:
10/04/2019
Last modified:
07/11/2023

Description

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:* 2.24.1 (excluding)
cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:* 2.24.1 (excluding)