Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1905

Опубликовано: 06 окт. 2020
Источник: nvd
CVSS3: 3.3
CVSS2: 4.3
EPSS Низкий

Описание

Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*
Версия до 2.20.185 (исключая)

EPSS

Процентиль: 51%
0.00276
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-340
CWE-330

Связанные уязвимости

github
больше 3 лет назад

Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.

EPSS

Процентиль: 51%
0.00276
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-340
CWE-330