Vulnerability Description
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Shazam | < 9.25.0 |
Related Weaknesses (CWE)
References
- https://support.apple.com/HT210744Vendor Advisory
- https://support.apple.com/HT210745Vendor Advisory
- https://support.apple.com/HT210744Vendor Advisory
- https://support.apple.com/HT210745Vendor Advisory
FAQ
What is CVE-2019-8791?
CVE-2019-8791 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Process...
How severe is CVE-2019-8791?
CVE-2019-8791 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-8791?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Shazam.