CVE-2024-43093 - "Apache ExternalStorageFile Path Filter Bypass (Local Privilege Escalation)"

1 week ago 3
ARTICLE AD BOX
CVE ID : CVE-2024-43093
Published : Nov. 13, 2024, 6:15 p.m. | 24 minutes ago
Description : In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article