CVE-2023-34165 — Missing Authorization in Huawei Harmonyos
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 79.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16
Description
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-jm4w-v2xf-52jr: Unauthorized access vulnerability in the Save for later feature provided by AI Touch↗2023-06-16