CVE Vulnerabilities

CVE-2022-48301

Improper Preservation of Permissions

Published: Feb 09, 2023 | Modified: Mar 24, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability may restore the pre-installed apps that have been uninstalled.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Emui Huawei 11.0.1 (including) 11.0.1 (including)
Emui Huawei 12.0.0 (including) 12.0.0 (including)
Emui Huawei 12.0.1 (including) 12.0.1 (including)

References