PT-2024-26135 · Unknown · Mediaprovider.Java

Omar Eissa

·

Published

2024-07-01

·

Updated

2024-12-17

·

CVE-2024-34721

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MediaProvider.java (affected versions not specified)
Description The issue is related to improper input validation in the ensureFileColumns function of MediaProvider.java. This could lead to the disclosure of files owned by another user, resulting in local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

ASB-A-294406604
CVE-2024-34721

Affected Products

Mediaprovider.Java