Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-7922

Опубликовано: 23 фев. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests upon finding a corresponding opt parameter in the Bundle extras argument, which allows attackers to bypass an intended consent dialog and retrieve tokens for arbitrary OAuth scopes including the SID and LSID scopes, and consequently obtain access to a Google account, via a crafted application, as demonstrated by setting the has_permission=1 parameter value upon finding _opt_has_permission in that argument.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:play_services_sdk:*:*:*:*:*:*:*:*
Версия до 6.1 (включая)

EPSS

Процентиль: 27%
0.00095
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests upon finding a corresponding _opt_ parameter in the Bundle extras argument, which allows attackers to bypass an intended consent dialog and retrieve tokens for arbitrary OAuth scopes including the SID and LSID scopes, and consequently obtain access to a Google account, via a crafted application, as demonstrated by setting the has_permission=1 parameter value upon finding _opt_has_permission in that argument.

EPSS

Процентиль: 27%
0.00095
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-264