cvelist/2024/12xxx/CVE-2024-12993.json
2024-12-30 12:00:56 +00:00

81 lines
2.6 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-12993",
"ASSIGNER": "cvd@cert.pl",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Infinix devices contain a pre-loaded \"com.rlk.weathers\" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user\u2019s location without any privileges.\u00a0\nAfter multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere",
"cweId": "CWE-497"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Infinix Mobile",
"product": {
"product_data": [
{
"product_name": "com.rlk.weathers",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "7.0.0.037"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://cert.pl/en/posts/2024/12/CVE-2024-12993/",
"refsource": "MISC",
"name": "https://cert.pl/en/posts/2024/12/CVE-2024-12993/"
},
{
"url": "https://cert.pl/posts/2024/12/CVE-2024-12993/",
"refsource": "MISC",
"name": "https://cert.pl/posts/2024/12/CVE-2024-12993/"
}
]
},
"generator": {
"engine": "Vulnogram 0.2.0"
},
"source": {
"discovery": "UNKNOWN"
},
"credits": [
{
"lang": "en",
"value": "Szymon Chadam"
}
]
}