VDB
CVE-2022-20458
CVE-2022-20458
PUBLISHED
CVSS 5.5 MEDIUM
The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the StatusBarNotification.getKey() directly in logs, which could contain user's account name (i.e. PII), in Android "user" build.Product: AndroidVersions: Android-12LAndroid ID: A-205567776
EPSS 0.12% · 2.4th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.12%
2.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Android | * |
| android | 12.1 |
Timeline
- Jan 24, 2023 CVE Published
- Jan 25, 2023 EPSS Score
- Mar 6, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 16, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 6, 2023 EPSS Score
- Aug 15, 2023 EPSS Score
- Sep 25, 2023 EPSS Score
- Nov 4, 2023 EPSS Score
- Dec 15, 2023 EPSS Score
- Jan 24, 2024 EPSS Score