В приложении MapQuest Get Directions 10.16.1 для Android была обнаружена уязвимость. Эта уязвимость затрагивает функцию getDataColumn файла ExpoShareIntentModule.kt компонента com.mapquest.android.ace. Манипулирование приводит к обходу пути.
Атака должна осуществляться локально. Эксплойт общедоступен и может быть использован. С поставщиком заранее связались по поводу этой информации, но он никак не отреагировал.
Показать оригинальное описание (EN)
A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Характеристики атаки
Последствия
Строка CVSS v4.0