The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the StatusBarNotification.getKey() directly in logs, which could contain user's account name (i.e. PII), in Android "user" build.Product: AndroidVersions: Android-12LAndroid ID: A-205567776
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/aaos/2023-01-01 | Vendor Advisory |
Configurations
Information
Published : 2023-01-26 13:15
Updated : 2023-02-01 07:03
NVD link : CVE-2022-20458
Mitre link : CVE-2022-20458
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
- android