In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
References
Link | Resource |
---|---|
https://source.android.com/docs/security/bulletin/android-14 | Release Notes Vendor Advisory |
https://source.android.com/docs/security/bulletin/android-14 | Release Notes Vendor Advisory |
Configurations
History
21 Nov 2024, 07:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://source.android.com/docs/security/bulletin/android-14 - Release Notes, Vendor Advisory |
07 Nov 2023, 00:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* | |
CWE | CWE-532 | |
References | (MISC) https://source.android.com/docs/security/bulletin/android-14 - Release Notes, Vendor Advisory | |
First Time |
Google
Google android |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.4 |
30 Oct 2023, 18:21
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-30 18:15
Updated : 2024-11-21 07:42
NVD link : CVE-2023-21387
Mitre link : CVE-2023-21387
CVE.ORG link : CVE-2023-21387
JSON object : View
Products Affected
- android
CWE
CWE-532
Insertion of Sensitive Information into Log File