René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

79 lines
2.5 KiB
JSON

{
"id": "CVE-2022-20241",
"sourceIdentifier": "security@android.com",
"published": "2022-08-11T15:15:09.887",
"lastModified": "2022-08-13T02:18:24.527",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217185011"
},
{
"lang": "es",
"value": "En Messaging, se presenta la posibilidad de adjuntar un archivo privado a un mensaje SMS debido a una comprobaci\u00f3n de entrada inapropiada. Esto podr\u00eda conllevar a una divulgaci\u00f3n de informaci\u00f3n local sin ser necesarios privilegios de ejecuci\u00f3n adicionales. No es requerida una interacci\u00f3n del usuario para su explotaci\u00f3n. Producto: Android, Versiones: Android-13, ID de Android: A-217185011"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 3.3,
"baseSeverity": "LOW"
},
"exploitabilityScore": 1.8,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:google:android:13.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "89D7FFC2-22B6-4DE8-BB70-E588893C23D1"
}
]
}
]
}
],
"references": [
{
"url": "https://source.android.com/security/bulletin/android-13",
"source": "security@android.com",
"tags": [
"Vendor Advisory"
]
}
]
}