CVE-2019-8632
Estado: ModificadaMedia (6.5)—
Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be able to intercept analytics data.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.29%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-319
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-8632",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "product-security@apple.com",
"affectedData": [
{
"vendor": "Apple",
"product": "Texture-iOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "Texture 5.11.10 for iOS",
"versionType": "custom"
}
]
},
{
"vendor": "Apple",
"product": "Texture-Android",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "Texture 4.22.0.4 for Android",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-12-18T18:15:30.567",
"references": [
{
"url": "https://support.apple.com/HT210110",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT210111",
"tags": [
"Vendor Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://www.info-sec.ca/advisories/Texture.html",
"tags": [
"Third Party Advisory"
],
"source": "product-security@apple.com"
},
{
"url": "https://support.apple.com/HT210110",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.apple.com/HT210111",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.info-sec.ca/advisories/Texture.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Some analytics data was sent using HTTP rather than HTTPS. This was addressed by no longer sending this analytics data. This issue is fixed in Texture 5.11.10 for iOS, Texture 4.22.0.4 for Android. An attacker in a privileged network position may be able to intercept analytics data."
},
{
"lang": "es",
"value": "Algunos datos analíticos fueron enviados utilizando HTTP en lugar de HTTPS. Esto fue abordado al dejar de enviar estos datos analíticos. Este problema es corregido en Texture versión 5.11.10 para iOS, Texture versión 4.22.0.4 para Android. Un atacante en una posición de red privilegiada puede ser capaz de interceptar datos analíticos."
}
],
"lastModified": "2026-06-17T02:42:17.467",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:texture:*:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "1A174DBC-36E1-456B-A3BC-E3325E6DA618",
"versionEndExcluding": "4.22.0.4"
},
{
"criteria": "cpe:2.3:a:apple:texture:*:*:*:*:*:ios:*:*",
"vulnerable": true,
"matchCriteriaId": "E7E71850-7929-4027-B348-6B3EEA27A588",
"versionEndExcluding": "5.11.10"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "product-security@apple.com"
}