CVE Vulnerabilities

CVE-2022-22650

Improper Preservation of Permissions

Published: Mar 18, 2022 | Modified: Nov 02, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A plug-in may be able to inherit the applications permissions and access user data.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple 10.15 (including) 10.15.7 (excluding)
Mac_os_x Apple 10.15.7-security_update_2022-001 (including) 10.15.7-security_update_2022-001 (including)
Mac_os_x Apple 10.15.7-security_update_2022-002 (including) 10.15.7-security_update_2022-002 (including)
Macos Apple 11.6 (including) 11.6.5 (excluding)
Macos Apple 12.0 (including) 12.3 (excluding)
Macos Apple 10.15.7 (including) 10.15.7 (including)

References