CVE Vulnerabilities

CVE-2024-39674

Cleartext Storage of Sensitive Information

Published: Jul 25, 2024 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Emui Huawei 12.0.0 (including) 12.0.0 (including)
Emui Huawei 13.0.0 (including) 13.0.0 (including)
Emui Huawei 14.0.0 (including) 14.0.0 (including)
Harmonyos Huawei 2.0.0 (including) 2.0.0 (including)
Harmonyos Huawei 2.1.0 (including) 2.1.0 (including)
Harmonyos Huawei 3.0.0 (including) 3.0.0 (including)
Harmonyos Huawei 3.1.0 (including) 3.1.0 (including)
Harmonyos Huawei 4.0.0 (including) 4.0.0 (including)
Harmonyos Huawei 4.2.0 (including) 4.2.0 (including)

Potential Mitigations

References