CVE-2024-2045

medium

Description

Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.

References

https://github.com/oxen-io/session-android/

https://fluidattacks.com/advisories/newman/

Details

Source: Mitre, NVD

Published: 2024-03-01

Updated: 2024-03-01

Risk Information

CVSS v2

Base Score: 3.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:N/A:N

Severity: Low

CVSS v3

Base Score: 4.4

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

Severity: Medium