1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
References
| Link | Resource |
|---|---|
| https://app-updates.agilebits.com | Release Notes |
| https://support.1password.com/kb/202408a/ | Vendor Advisory |
Configurations
History
12 Aug 2024, 18:30
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:1password:1password:*:*:*:*:*:macos:*:* | |
| First Time |
1password 1password
1password |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| References | () https://app-updates.agilebits.com - Release Notes | |
| References | () https://support.1password.com/kb/202408a/ - Vendor Advisory |
06 Aug 2024, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-08-06 21:16
Updated : 2024-08-12 18:30
NVD link : CVE-2024-42219
Mitre link : CVE-2024-42219
JSON object : View
Products Affected
1password
- 1password
CWE
