PT-2022-24917 · Tasks.Org · Tasks.Org

Abaker

+1

·

Published

2022-10-25

·

Updated

2022-10-28

·

CVE-2022-39349

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tasks.org versions prior to 12.7.1 Tasks.org versions prior to 13.0.1
Description The Tasks.org Android app has a sensitive information disclosure issue. The app's ShareLinkActivity.kt activity handles "share" intents and may copy files from internal storage to external storage if the file paths in the intents are not validated. This allows malicious applications on the same device to access sensitive information, including notes, preferences, and encrypted CalDav integration credentials.
Recommendations For versions prior to 12.7.1, update to version 12.7.1 or later. For versions prior to 13.0.1, update to version 13.0.1 or later.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2022-39349
GHSA-8X58-CG74-8JG8

Affected Products

Tasks.Org