CVE Vulnerabilities

CVE-2022-20278

Insertion of Sensitive Information into Log File

Published: Aug 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205130113

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle13.0 (including)13.0 (including)

Potential Mitigations

References