Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7m8-qmv8-g6vm

Опубликовано: 13 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41

EPSS

Процентиль: 38%
0.00166
Низкий

7.8 High

CVSS3

Дефекты

CWE-22
CWE-427

Связанные уязвимости

CVSS3: 8.9
nvd
около 3 лет назад

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41

EPSS

Процентиль: 38%
0.00166
Низкий

7.8 High

CVSS3

Дефекты

CWE-22
CWE-427