« Volver al listado

CVE-2019-8791

Estado: ModificadaMedia (6.1)—

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-8791",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "Shazam-Android",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "Shazam Android App Version 9.25.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "Shazam-iOS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "Shazam iOS App Version 12.11.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-18T18:15:41.647",
  "references": [
    {
      "url": "https://support.apple.com/HT210744",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/HT210745",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/HT210744",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/HT210745",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect."
    },
    {
      "lang": "es",
      "value": "Se presentó un problema en el análisis de los esquemas de URL. Este problema fue abordado con una comprobación de URL mejorada. Este problema fue corregido en Shazam Android App versión 9.25.0 y Shazam iOS App versión 12.11.0. El procesamiento de una URL diseñada maliciosamente puede conllevar a un redireccionamiento abierto."
    }
  ],
  "lastModified": "2026-06-17T02:42:37.387",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:shazam:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "901CD767-C378-4185-A443-DED17BEBAF60",
              "versionEndExcluding": "9.25.0"
            },
            {
              "criteria": "cpe:2.3:a:apple:shazam:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90312868-463B-4AD7-92FE-AD399DEFD3ED",
              "versionEndExcluding": "12.11.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}