Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rx8-chp2-fvxf

Опубликовано: 07 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.

EPSS

Процентиль: 33%
0.00134
Низкий

5 Medium

CVSS3

Дефекты

CWE-22
CWE-24

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.

EPSS

Процентиль: 33%
0.00134
Низкий

5 Medium

CVSS3

Дефекты

CWE-22
CWE-24