PT-2023-15912 · Unknown · Codenameone

CVE-2022-4903

·

Published

2023-02-10

·

Updated

2024-05-17

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodenameOne version 7.0.70
Description A vulnerability was found in CodenameOne, classified as problematic. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. The complexity of an attack is rather high and the exploitability is told to be difficult.
Recommendations Upgrade to version 7.0.71 to address this issue. As a temporary workaround, consider restricting the use of implicit intent for sensitive communication until the patch is applied.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4903
GHSA-P6XQ-9H8R-V544

Affected Products

Codenameone