This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regions of the disk.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2024/Mar/21 | Mailing List |
http://seclists.org/fulldisclosure/2024/Mar/21 | Mailing List |
https://support.apple.com/en-us/HT214084 | Vendor Advisory |
https://support.apple.com/en-us/HT214084 | Vendor Advisory |
Configurations
History
07 Dec 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2024/Mar/21 - Mailing List | |
References | () https://support.apple.com/en-us/HT214084 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
CWE | CWE-59 | |
First Time |
Apple macos
Apple |
13 Mar 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Mar 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-08 02:15
Updated : 2024-12-07 03:15
NVD link : CVE-2024-23285
Mitre link : CVE-2024-23285
JSON object : View
Products Affected
apple
- macos
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')