109 lines
3.1 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2018-19111",
"sourceIdentifier": "cve@mitre.org",
"published": "2018-11-08T08:29:00.573",
"lastModified": "2019-10-03T00:03:26.223",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS."
},
{
"lang": "es",
"value": "La aplicaci\u00f3n Google Cardboard 1.8 para Android y 1.2 para iOS env\u00eda informaci\u00f3n en texto claro potencialmente privada al sitio web de Unity 3D Stats, tal y como lo demuestran la marca, el modelo y el sistema operativo del dispositivo."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:cardboard:1.2:*:*:*:*:iphone_os:*:*",
"matchCriteriaId": "46A888AB-7997-450F-A49E-5BAD595C9169"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:cardboard:1.8:*:*:*:*:android:*:*",
"matchCriteriaId": "5D0AD3A8-A4C8-40F6-AF5A-7BA8EF429F55"
}
]
}
]
}
],
"references": [
{
"url": "https://www.info-sec.ca/advisories/Google-Cardboard.html",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}