CVE-2010-1760

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
19/08/2010
Last modified:
11/04/2025

Description

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:* r58408 (including)
cpe:2.3:a:apple:webkit:r50173:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r56187:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r56188:*:*:*:*:*:*:*
cpe:2.3:a:apple:webkit:r56379:*:*:*:*:*:*:*