Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q5g-gj85-746p

Опубликовано: 25 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair

The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair

EPSS

Процентиль: 22%
0.00073
Низкий

7.8 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.8
nvd
больше 2 лет назад

The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair

EPSS

Процентиль: 22%
0.00073
Низкий

7.8 High

CVSS3

Дефекты

CWE-798