CVE-2022-20351
published 2022-10-11CVE-2022-20351: In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.12%
2.5th percentile
In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224771921
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_providers_contactsprovider | >= 10:0 < 10:2022-10-01 | 10:2022-10-01 |
| platform | packages_providers_contactsprovider | >= 11:0 < 11:2022-10-01 | 11:2022-10-01 |
| platform | packages_providers_contactsprovider | >= 12:0 < 12:2022-10-01 | 12:2022-10-01 |
| platform | packages_providers_contactsprovider | >= 12L:0 < 12L:2022-10-01 | 12L:2022-10-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-20351: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20351
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-224771921
vendor_android·2022-10-01·CVSS 5.5
CVE-2022-20351 [MEDIUM] CVE-2022-20351: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20351
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-224771921
Android Security Bulletin 2022-10-01
CVE: CVE-2022-20351
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11, 12, 12L
References: A-224771921
GHSA
GHSA-w76c-fv26-8q58: In queryInternal of CallLogProvider
ghsa_unreviewed·2022-10-12
CVE-2022-20351 [MEDIUM] CWE-89 GHSA-w76c-fv26-8q58: In queryInternal of CallLogProvider
In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224771921
OSV
CVE-2022-20351: In queryInternal of CallLogProvider
osv·2022-10-01
CVE-2022-20351 CVE-2022-20351: In queryInternal of CallLogProvider
In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published