2024-07-14 02:06:08 +00:00

80 lines
2.6 KiB
JSON

{
"id": "CVE-2021-0734",
"sourceIdentifier": "security@android.com",
"published": "2022-08-11T15:15:09.180",
"lastModified": "2022-08-13T02:13:52.303",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local information disclosure of an installed package, without proper query permissions, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-189122911"
},
{
"lang": "es",
"value": "En Settings, es posible determinar si una app est\u00e1 instalada sin permisos de consulta, debido a la divulgaci\u00f3n de informaci\u00f3n por canal lateral. Esto podr\u00eda conllevar a una divulgaci\u00f3n de informaci\u00f3n local de un paquete instalado, sin los permisos de consulta apropiados, sin ser necesarios privilegios de ejecuci\u00f3n adicionales. No es requerida una interacci\u00f3n del usuario para su explotaci\u00f3n. Producto: Android, Versiones: Android-13, ID de Android: A-189122911"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-668"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:google:android:13.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "89D7FFC2-22B6-4DE8-BB70-E588893C23D1"
}
]
}
]
}
],
"references": [
{
"url": "https://source.android.com/security/bulletin/android-13",
"source": "security@android.com",
"tags": [
"Vendor Advisory"
]
}
]
}