Improper Application of HTTP Proxy Settings in WebKitGTK and WPE WebKit Leads to Deanonymization

Improper Application of HTTP Proxy Settings in WebKitGTK and WPE WebKit Leads to Deanonymization

CVE-2019-11070 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:N

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.

Learn more about our Web Application Penetration Testing UK.