CVE-2022-0343

A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyond 24.2
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:perfetto:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:38

Type Values Removed Values Added
CVSS v2 : 4.6
v3 : 7.8
v2 : 4.6
v3 : 3.3
References () https://android-review.googlesource.com/c/platform/external/perfetto/+/1999296/ - Patch, Third Party Advisory () https://android-review.googlesource.com/c/platform/external/perfetto/+/1999296/ - Patch, Third Party Advisory

07 Apr 2022, 16:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.6
v3 : 7.8
CPE cpe:2.3:a:google:perfetto:*:*:*:*:*:*:*:*
References (MISC) https://android-review.googlesource.com/c/platform/external/perfetto/+/1999296/ - (MISC) https://android-review.googlesource.com/c/platform/external/perfetto/+/1999296/ - Patch, Third Party Advisory
CWE NVD-CWE-noinfo

29 Mar 2022, 17:19

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-29 16:15

Updated : 2024-11-21 06:38


NVD link : CVE-2022-0343

Mitre link : CVE-2022-0343

CVE.ORG link : CVE-2022-0343


JSON object : View

Products Affected

google

  • perfetto
CWE
CWE-275

Permission Issues

NVD-CWE-noinfo