CVE-2024-10382

There exists a code execution vulnerability in the Car App Android Jetpack Library. In the CarAppService desrialization logic is used that allows for arbitrary java classes to be constructed. In combination with other gadgets, this can lead to arbitrary code execution. An attacker needs to have an app on a victims Android device that uses the CarAppService Class and the victim would need to install a malicious app alongside it. We recommend upgrading the library past versionĀ 1.7.0-beta02
Configurations

No configuration.

History

20 Nov 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-94

20 Nov 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-20 11:15

Updated : 2024-11-20 17:35


NVD link : CVE-2024-10382

Mitre link : CVE-2024-10382

CVE.ORG link : CVE-2024-10382


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data

CWE-94

Improper Control of Generation of Code ('Code Injection')