PT-2023-15912 · Unknown · Codenameone

CVE-2022-4903

·

Publicado

2023-02-10

·

Atualizado

2024-05-17

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodenameOne version 7.0.70
Description A vulnerability was found in CodenameOne, classified as problematic. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. The complexity of an attack is rather high and the exploitability is told to be difficult.
Recommendations Upgrade to version 7.0.71 to address this issue. As a temporary workaround, consider restricting the use of implicit intent for sensitive communication until the patch is applied.

Exploit

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-4903
GHSA-P6XQ-9H8R-V544

Produtos afetados

Codenameone