CVE-2021-0538
published 2021-06-22CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to…
PriorityP335high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.11%
1.8th percentile
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178821491
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| platform | frameworks_base | >= 11:0 < 11:2021-06-01 | 11:2021-06-01 |
| platform | frameworks_opt_telephony | >= 11:0 < 11:2021-06-01 | 11:2021-06-01 |
| platform | packages_services_telephony | >= 11:0 < 11:2021-06-01 | 11:2021-06-01 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hr9w-xmr5-649g: In onCreate of EmergencyCallbackModeExitDialog
ghsa_unreviewed·2022-05-24
CVE-2021-0538 [HIGH] CWE-1021 GHSA-hr9w-xmr5-649g: In onCreate of EmergencyCallbackModeExitDialog
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178821491
GHSA
DoS vulnerability in bundled XStream library in Jenkins Core
ghsa·2022-02-10·CVSS 7.5
CVE-2022-0538 [HIGH] CWE-502 DoS vulnerability in bundled XStream library in Jenkins Core
DoS vulnerability in bundled XStream library in Jenkins Core
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier is affected by the XStream library’s vulnerability [CVE-2021-43859](https://x-stream.github.io/CVE-2021-43859.html). This library is used by Jenkins to serialize and deserialize various XML files, like global and job `config.xml`, `build.xml`, and numerous others.
This allows attackers able to submit crafted XML files to Jenkins to be parsed as configuration, e.g. through the `POST config.xml` API, to cause a denial of service (DoS).
OSV
CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog
osv·2021-06-01
CVE-2021-0538 CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Red Hat
jenkins: DoS vulnerability in bundled XStream library
vendor_redhat·2022-02-09·CVSS 7.5
CVE-2022-0538 [HIGH] CWE-502 jenkins: DoS vulnerability in bundled XStream library
jenkins: DoS vulnerability in bundled XStream library
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
A denial of service (DoS) flaw was found in Jenkins. This flaw allows an attacker to define custom XStream converters that do not protect against the vulnerability in CVE-2021-43859, allowing for uncontrolled resource consumption.
Package: jenkins (Red Hat Fuse 7) - Not affected
Package: jenkins (Red Hat OpenShift Container Platform 3.11) - Not affected
Package: jenkins (Red Hat OpenShift Container Platform 4) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-22
Published