CVE-2012-0647: Apple Safari

Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.

WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header.

Affected products

  • Apple Safari: any version; up to and including 5.1.3; version 1.0 only; version 1.0.0 only; version 1.0.0b1 only; version 1.0.0b2 only; …

Published 2012-03-12. Last modified 2026-06-16.