2024-12-08 03:06:42 +00:00

123 lines
3.7 KiB
JSON

{
"id": "CVE-2020-8274",
"sourceIdentifier": "support@hackerone.com",
"published": "2021-01-06T21:15:14.473",
"lastModified": "2024-11-21T05:38:38.043",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device."
},
{
"lang": "es",
"value": "Citrix Secure Mail para Android versiones anteriores a 20.11.0, sufre de un Control Inapropiado de la Generaci\u00f3n de C\u00f3digo (\"Code Injection\") al permitir el acceso no autenticado para leer los datos almacenados en Secure Mail. Tome en cuenta que se necesitar\u00eda instalar una aplicaci\u00f3n maliciosa en el dispositivo Android o un actor de amenazas tendr\u00eda que ejecutar c\u00f3digo arbitrario en el dispositivo Android"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"baseScore": 4.3,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "support@hackerone.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:citrix:secure_mail:*:*:*:*:*:android:*:*",
"versionEndExcluding": "20.11.0",
"matchCriteriaId": "62E7A966-BD38-419D-8072-806F1E8E4FBD"
}
]
}
]
}
],
"references": [
{
"url": "https://support.citrix.com/article/CTX286763",
"source": "support@hackerone.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://support.citrix.com/article/CTX286763",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
]
}