CVE-2019-8791
Estado: ModificadaMedia (6.1)—
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.12%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-601
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-8791",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "Apple",
"product": "Shazam-Android",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "Shazam Android App Version 9.25.0",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "Shazam-iOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "Shazam iOS App Version 12.11.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-12-18T18:15:41.647",
"references": [
{
"url": "https://support.apple.com/HT210744",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT210745",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT210744",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT210745",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-601"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect."
},
{
"lang": "es",
"value": "Se presentó un problema en el análisis de los esquemas de URL. Este problema fue abordado con una comprobación de URL mejorada. Este problema fue corregido en Shazam Android App versión 9.25.0 y Shazam iOS App versión 12.11.0. El procesamiento de una URL diseñada maliciosamente puede conllevar a un redireccionamiento abierto."
}
],
"lastModified": "2026-06-17T02:42:37.387",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:shazam:*:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "901CD767-C378-4185-A443-DED17BEBAF60",
"versionEndExcluding": "9.25.0"
},
{
"criteria": "cpe:2.3:a:apple:shazam:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "90312868-463B-4AD7-92FE-AD399DEFD3ED",
"versionEndExcluding": "12.11.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}