CVE-2015-5828

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
09/10/2015
Last modified:
12/04/2025

Description

The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 8.0.8 (including)