Описание
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.20.185 (исключая)
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*
EPSS
Процентиль: 51%
0.00276
Низкий
3.3 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-340
CWE-330
Связанные уязвимости
github
больше 3 лет назад
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.
EPSS
Процентиль: 51%
0.00276
Низкий
3.3 Low
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-340
CWE-330