VDB

CVE-2022-20458

CVE-2022-20458 PUBLISHED CVSS 5.5 MEDIUM

The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the StatusBarNotification.getKey() directly in logs, which could contain user's account name (i.e. PII), in Android "user" build.Product: AndroidVersions: Android-12LAndroid ID: A-205567776

EPSS 0.12% · 2.4th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.12%
2.4th percentile

Affected Products

VendorProductVersions
n/aAndroid*
googleandroid12.1

Timeline

  • Jan 24, 2023 CVE Published
  • Jan 25, 2023 EPSS Score
  • Mar 6, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 16, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 6, 2023 EPSS Score
  • Aug 15, 2023 EPSS Score
  • Sep 25, 2023 EPSS Score
  • Nov 4, 2023 EPSS Score
  • Dec 15, 2023 EPSS Score
  • Jan 24, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›