123 lines
3.6 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2020-1902",
"sourceIdentifier": "cve-assign@fb.com",
"published": "2020-10-06T18:15:15.627",
"lastModified": "2021-09-14T18:16:22.753",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A user running a quick search on a highly forwarded message on WhatsApp for Android from v2.20.108 to v2.20.140 or WhatsApp Business for Android from v2.20.35 to v2.20.49 could have been sent to the Google service over plain HTTP."
},
{
"lang": "es",
"value": "Un usuario que realiza una b\u00fasqueda r\u00e1pida en un mensaje altamente reenviado en WhatsApp para Android desde versiones v2.20.108 hasta v2.20.140 o WhatsApp Business para Android desde versiones v2.20.35 hasta v2.20.49, podr\u00eda haber sido enviado al servicio de Google por medio de un HTTP plano"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
},
{
"source": "cve-assign@fb.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*",
"versionStartIncluding": "2.20.108",
"versionEndIncluding": "2.20.140",
"matchCriteriaId": "CA96B32C-5673-4B36-AE2C-D318744B0E25"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*",
"versionStartIncluding": "2.20.35",
"versionEndIncluding": "2.20.49",
"matchCriteriaId": "D098DF3C-6EA3-470E-865C-601827ABFB35"
}
]
}
]
}
],
"references": [
{
"url": "https://www.whatsapp.com/security/advisories/2020/",
"source": "cve-assign@fb.com",
"tags": [
"Vendor Advisory"
]
}
]
}