CRITICAL · 9.8

CVE-2018-12910

The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

Vulnerability Description

The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GnomeLibsoup2.63.2
CanonicalUbuntu Linux14.04
DebianDebian Linux8.0
RedhatAnsible Tower3.3
RedhatOpenshift Container Platform3.11
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Workstation7.0
OpensuseLeap15.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-12910?

CVE-2018-12910 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

How severe is CVE-2018-12910?

CVE-2018-12910 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-12910?

Check the references section above for vendor advisories and patch information. Affected products include: Gnome Libsoup, Canonical Ubuntu Linux, Debian Debian Linux, Redhat Ansible Tower, Redhat Openshift Container Platform.