Overview
- Description
- An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.
- Source
- product-security@apple.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-601
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apple:shazam:*:*:*:*:*:iphone_os:*:*", "vulnerable": true, "matchCriteriaId": "901CD767-C378-4185-A443-DED17BEBAF60", "versionEndExcluding": "9.25.0" }, { "criteria": "cpe:2.3:a:apple:shazam:*:*:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "90312868-463B-4AD7-92FE-AD399DEFD3ED", "versionEndExcluding": "12.11.0" } ], "operator": "OR" } ] } ]