PT-2024-19077 · Unknown · Openharmony

Published

2024-03-04

·

Updated

2024-12-16

·

CVE-2024-21826

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenHarmony versions prior to 3.2.4
Description The issue allows a local attacker to cause a sensitive information leak through insecure storage. A local attacker can exploit this to gain access to sensitive information.
Recommendations For OpenHarmony versions prior to 3.2.4, update to a version newer than 3.2.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information stored by OpenHarmony until a patch is available.

Fix

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-21826

Affected Products

Openharmony