CVE-2020-0250
published 2020-08-11CVE-2020-0250: In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.15%
4.4th percentile
In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154934934
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_services_telephony | >= 10:0 < 10:2020-08-01 | 10:2020-08-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2020-0250: Android Security Bulletin 2020-08-01
CVE: CVE-2020-0250
Severity: HIGH
Type: ID
Affected AOSP versions: 10
References: A-154934934
vendor_android·2020-08-01·CVSS 5.5
CVE-2020-0250 [MEDIUM] CVE-2020-0250: Android Security Bulletin 2020-08-01
CVE: CVE-2020-0250
Severity: HIGH
Type: ID
Affected AOSP versions: 10
References: A-154934934
Android Security Bulletin 2020-08-01
CVE: CVE-2020-0250
Severity: HIGH
Type: ID
Affected AOSP versions: 10
References: A-154934934
GHSA
GHSA-5phg-ff74-gp62: In requestCellInfoUpdateInternal of PhoneInterfaceManager
ghsa_unreviewed·2022-05-24
CVE-2020-0250 [MEDIUM] CWE-200 GHSA-5phg-ff74-gp62: In requestCellInfoUpdateInternal of PhoneInterfaceManager
In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-154934934
OSV
CVE-2020-0250: In requestCellInfoUpdateInternal of PhoneInterfaceManager
osv·2020-08-01
CVE-2020-0250 CVE-2020-0250: In requestCellInfoUpdateInternal of PhoneInterfaceManager
In requestCellInfoUpdateInternal of PhoneInterfaceManager.java, there is a missing permission check. This could lead to local information disclosure of location data with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
bugzilla·2020-09-22·CVSS 5.3
CVE-2020-25640 [MEDIUM] CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
A flaw was found in WildFly. Resource adapter logs plain text JMS password at warning level on connection error.
Discussion:
External References:
https://github.com/amqphub/amqp-10-resource-adapter/issues/13
---
Created wildfly tracking bugs for this issue:
Affects: fedora-all [bug 1882385]
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2021:0250 https://access.redhat.com/errata/RHSA-2021:0250
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6
Via RHSA-2021:0246 https://access.redhat.com/errata/RHSA-2021:0246
---
This issue has bee
Bugzilla
CVE-2020-25633 resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling
bugzilla·2020-09-15·CVSS 5.3
CVE-2020-25633 [MEDIUM] CVE-2020-25633 resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling
CVE-2020-25633 resteasy-client: potential sensitive information leakage in JAX-RS RESTEasy Client's WebApplicationException handling
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information in headers, cookies and body when the server got WebApplicationException from the RESTEasy client call.
Discussion:
Affected artifacts:
https://maven.repository.redhat.com/ga/org/jboss/resteasy/resteasy-client/
https://maven.repository.redhat.com/ga/org/jboss/resteasy/resteasy-client-microprofile/
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2021:0250 https://access.redhat.com/errata/RHSA-2021:0250
---
This issue has
2020-08-11
Published