CVE Vulnerabilities

CVE-2024-20050

Insecure Storage of Sensitive Information

Published: Apr 01, 2024 | Modified: Apr 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Yocto Linuxfoundation 3.3 (including) 3.3 (including)
Rdk-b Rdkcentral 2022q3 (including) 2022q3 (including)
Android Google 12.0 (including) 12.0 (including)
Android Google 13.0 (including) 13.0 (including)
Android Google 14.0 (including) 14.0 (including)
Openwrt Openwrt 19.07.0 (including) 19.07.0 (including)
Openwrt Openwrt 21.02.0 (including) 21.02.0 (including)

References