PT-2023-15912 · Unknown · Codenameone
CVE-2022-4903
·
Publicado
2023-02-10
·
Atualizado
2024-05-17
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CodenameOne version 7.0.70
Description
A vulnerability was found in CodenameOne, classified as problematic. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. The complexity of an attack is rather high and the exploitability is told to be difficult.
Recommendations
Upgrade to version 7.0.71 to address this issue. As a temporary workaround, consider restricting the use of implicit intent for sensitive communication until the patch is applied.
Exploit
Correção
Exposure of Resource to Wrong Sphere
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Codenameone