CVE-2021-1026
published 2021-12-15CVE-2021-1026: In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.6th percentile
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194798757
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | packages_modules_wifi | >= 12:0 < 12:2021-12-01 | 12:2021-12-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-58f3-gjmv-9j5x: In startRanging of RttServiceImpl
ghsa_unreviewed·2021-12-16
CVE-2021-1026 [MEDIUM] CWE-203 GHSA-58f3-gjmv-9j5x: In startRanging of RttServiceImpl
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-194798757
OSV
CVE-2021-1026: In startRanging of RttServiceImpl
osv·2021-12-01
CVE-2021-1026 CVE-2021-1026: In startRanging of RttServiceImpl
In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus
vendor_redhat·2022-11-28·CVSS 7.5
CVE-2022-4147 [HIGH] CWE-1026 quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus
quarkus-vertx-http: Security misconfiguration of CORS : OWASP A05_2021 level in Quarkus
Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request.
A vulnerability was found in Quarkus. The Quarkus CORS filter allows simple GET and POST requests with an invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest have no event listeners registered on the object returned by the XMLHttpRequest upload property, and have no ReadableStream object used in the request.
No detection rules found.
No public exploits indexed.
2021-12-15
Published