CVE-2022-20011
published 2022-05-10CVE-2022-20011: In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.13%
2.8th percentile
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-214999128
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | android-platform-frameworks-base | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2022-05-01 | 10:2022-05-01 |
| platform | frameworks_base | >= 11:0 < 11:2022-05-01 | 11:2022-05-01 |
| platform | frameworks_base | >= 12:0 < 12:2022-05-01 | 12:2022-05-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2022-05-01 | 12L:2022-05-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-20011: Android Security Bulletin 2022-05-01
CVE: CVE-2022-20011
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-214999128
vendor_android·2022-05-01·CVSS 5.5
CVE-2022-20011 [MEDIUM] CVE-2022-20011: Android Security Bulletin 2022-05-01
CVE: CVE-2022-20011
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-214999128
Android Security Bulletin 2022-05-01
CVE: CVE-2022-20011
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-214999128
Debian
CVE-2022-20011: android-platform-frameworks-base - In getArray of NotificationManagerService.java , there is a possible leak of one...
vendor_debian·2022·CVSS 5.5
CVE-2022-20011 [MEDIUM] CVE-2022-20011: android-platform-frameworks-base - In getArray of NotificationManagerService.java , there is a possible leak of one...
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-214999128
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-fhf6-wwc5-f233: In getArray of NotificationManagerService
ghsa_unreviewed·2022-05-11
CVE-2022-20011 [MEDIUM] CWE-862 GHSA-fhf6-wwc5-f233: In getArray of NotificationManagerService
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-214999128
OSV
CVE-2022-20011: In getArray of NotificationManagerService
osv·2022-05-10·CVSS 5.5
CVE-2022-20011 [MEDIUM] CVE-2022-20011: In getArray of NotificationManagerService
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-214999128
OSV
CVE-2022-20011: In getArray of NotificationManagerService
osv·2022-05-01
CVE-2022-20011 CVE-2022-20011: In getArray of NotificationManagerService
In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to missing check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-10
Published