Vulnerability Description
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Icloud | < 7.17 |
| Apple | Itunes | < 12.10.4 |
| Apple | Safari | < 13.0.5 |
| Apple | Ipados | < 13.3.1 |
| Apple | Iphone Os | < 13.3.1 |
| Apple | Tvos | < 13.3.1 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
Related Weaknesses (CWE)
References
- https://support.apple.com/en-us/HT210918Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210920Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210922Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210923Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210947Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210948Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210918Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210920Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210922Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210923Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210947Release NotesVendor Advisory
- https://support.apple.com/en-us/HT210948Release NotesVendor Advisory
FAQ
What is CVE-2020-3864?
CVE-2020-3864 is a vulnerability with a CVSS score of 7.8 (HIGH). A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and ...
How severe is CVE-2020-3864?
CVE-2020-3864 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3864?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Icloud, Apple Itunes, Apple Safari, Apple Ipados, Apple Iphone Os.