In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.
2019-01-11T18:29:00.453
2024-11-21T02:52:41.123
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | apple_tv | < 9.2.2 | Yes |
Operating System | apple | iphone_os | < 9.3.3 | Yes |
Operating System | apple | mac_os | < 10.11.6 | Yes |