
Cloud Vulnerability DB
A community-led vulnerabilities database
An input validation vulnerability (CVE-2019-8736) was discovered in the CUPS component of macOS systems. The vulnerability was disclosed and patched in October 2019, affecting macOS versions prior to Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. The issue specifically impacted the CUPS printing system in macOS High Sierra 10.13.6, macOS Mojave 10.14.6, and macOS Catalina 10.15 (Apple Security).
The vulnerability stems from an input validation issue in the CUPS (Common Unix Printing System) component. The security flaw was addressed by implementing improved input validation mechanisms. The vulnerability has been assigned a CVSS v3.1 Base Score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, indicating network accessibility with low attack complexity (NVD).
When exploited, this vulnerability allows an attacker in a privileged network position to potentially leak sensitive user information. The impact is primarily focused on data confidentiality, with no direct impact on system integrity or availability (Apple Security).
The vulnerability requires the attacker to be in a privileged network position to exploit the flaw. The attack vector is network-accessible, requiring low attack complexity but does need low privileges to execute (NVD).
Apple addressed this vulnerability by releasing security updates in macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006. Users are advised to update their systems to these versions or later to protect against this vulnerability (Apple Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."