Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29580

Опубликовано: 13 дек. 2022
Источник: nvd
CVSS3: 8.9
CVSS3: 7.8
EPSS Низкий

Описание

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:google_search:*:*:*:*:*:android:*:*
Версия до 13.41 (исключая)

EPSS

Процентиль: 38%
0.00166
Низкий

8.9 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-427
CWE-22

Связанные уязвимости

CVSS3: 7.8
github
около 3 лет назад

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41

EPSS

Процентиль: 38%
0.00166
Низкий

8.9 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-427
CWE-22