René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

109 lines
3.1 KiB
JSON

{
"id": "CVE-2018-19111",
"sourceIdentifier": "cve@mitre.org",
"published": "2018-11-08T08:29:00.573",
"lastModified": "2019-10-03T00:03:26.223",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS."
},
{
"lang": "es",
"value": "La aplicaci\u00f3n Google Cardboard 1.8 para Android y 1.2 para iOS env\u00eda informaci\u00f3n en texto claro potencialmente privada al sitio web de Unity 3D Stats, tal y como lo demuestran la marca, el modelo y el sistema operativo del dispositivo."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-319"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:cardboard:1.2:*:*:*:*:iphone_os:*:*",
"matchCriteriaId": "46A888AB-7997-450F-A49E-5BAD595C9169"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:google:cardboard:1.8:*:*:*:*:android:*:*",
"matchCriteriaId": "5D0AD3A8-A4C8-40F6-AF5A-7BA8EF429F55"
}
]
}
]
}
],
"references": [
{
"url": "https://www.info-sec.ca/advisories/Google-Cardboard.html",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}