CVE-2022-4903

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-4903
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4903.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-4903
Aliases
Published
2023-02-10T15:15:11Z
Modified
2024-05-23T01:26:44.143921Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 7.0.71 is able to address this issue. The patch is identified as dad49c9ef26a598619fc48d2697151a02987d478. It is recommended to upgrade the affected component. VDB-220470 is the identifier assigned to this vulnerability.

References

Affected packages

Git / github.com/codenameone/codenameone

Affected ranges

Type
GIT
Repo
https://github.com/codenameone/codenameone
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

7.*

7.0.65
7.0.66
7.0.67
7.0.68
7.0.69
7.0.70

v3.*

v3.5
v3.6
v3.7.3
v3.8.3

v4.*

v4.0
v4.1
v4.2
v4.3

v5.*

v5.0

v6.*

v6.0

v7.*

v7.0
v7.0.13
v7.0.14
v7.0.15
v7.0.16
v7.0.17
v7.0.18
v7.0.19
v7.0.20
v7.0.21
v7.0.22
v7.0.23
v7.0.24
v7.0.25
v7.0.26
v7.0.27
v7.0.28
v7.0.29
v7.0.30
v7.0.31
v7.0.32
v7.0.33
v7.0.34
v7.0.35
v7.0.36
v7.0.37
v7.0.38
v7.0.39
v7.0.40
v7.0.41
v7.0.42
v7.0.43
v7.0.44
v7.0.45
v7.0.46
v7.0.47
v7.0.48
v7.0.49
v7.0.50
v7.0.51
v7.0.52
v7.0.53
v7.0.54
v7.0.55
v7.0.56
v7.0.57
v7.0.58
v7.0.59
v7.0.60
v7.0.61
v7.0.62
v7.0.63
v7.0.64
v7.0.8-b1

Other

version7