PT-2023-18062 · Unknown · Statushints.Java

Published

2023-08-01

·

Updated

2023-08-21

·

CVE-2023-21283

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue is related to a confused deputy in multiple functions of StatusHints.java, which could lead to local information disclosure. User interaction is needed for exploitation, and no additional execution privileges are required. This could potentially reveal images across users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

ASB-A-280797684
CVE-2023-21283

Affected Products

Statushints.Java