The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the StatusBarNotification.getKey() directly in logs, which could contain user's account name (i.e. PII), in Android "user" build.Product: AndroidVersions: Android-12LAndroid ID: A-205567776
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/aaos/2023-01-01 | Vendor Advisory |
https://source.android.com/security/bulletin/aaos/2023-01-01 | Vendor Advisory |
Configurations
History
21 Nov 2024, 06:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://source.android.com/security/bulletin/aaos/2023-01-01 - Vendor Advisory | |
Summary |
|
Information
Published : 2023-01-26 21:15
Updated : 2024-11-21 06:42
NVD link : CVE-2022-20458
Mitre link : CVE-2022-20458
CVE.ORG link : CVE-2022-20458
JSON object : View
Products Affected
- android
CWE
CWE-532
Insertion of Sensitive Information into Log File