CVE-2022-43451 - CERT CVE
ID CVE-2022-43451
Sažetak OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.
Reference
CVSS
Base: 6.5
Impact: 4.0
Exploitability:2.0
Pristup
VektorSloženostAutentikacija
LOCAL LOW -
Impact
PovjerljivostCjelovitostDostupnost
NONE HIGH NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Zadnje važnije ažuriranje 07-11-2022 - 02:16
Objavljeno 03-11-2022 - 20:15