Refine your search

1 vulnerability found for appstore by vivo

CVE-2020-12483 (GCVE-0-2020-12483)
Vulnerability from cvelistv5
Published
2021-03-23 16:15
Modified
2024-09-16 22:56
CWE
  • CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Summary
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.
References
Impacted products
Vendor Product Version
vivo appstore Version: 8.12.0.0   < 8.12.0.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T11:56:52.105Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://www.vivo.com/en/support/security-advisory-detail?id=1"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "appstore",
          "vendor": "vivo",
          "versions": [
            {
              "lessThan": "8.12.0.0",
              "status": "affected",
              "version": "8.12.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "datePublic": "2021-03-22T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-601",
              "description": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2021-03-23T16:15:00.000Z",
        "orgId": "c6f5cd8e-fe3d-4460-82c2-f8a4e7b272c8",
        "shortName": "Vivo"
      },
      "references": [
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://www.vivo.com/en/support/security-advisory-detail?id=1"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "AppStore Remote Download and Installation Vulnerability",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "security@vivo.com",
          "DATE_PUBLIC": "2021-03-22T16:00:00.000Z",
          "ID": "CVE-2020-12483",
          "STATE": "PUBLIC",
          "TITLE": "AppStore Remote Download and Installation Vulnerability"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "appstore",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_name": "8.12.0.0",
                            "version_value": "8.12.0.0"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "vivo"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-601 URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.vivo.com/en/support/security-advisory-detail?id=1",
              "refsource": "CONFIRM",
              "url": "https://www.vivo.com/en/support/security-advisory-detail?id=1"
            }
          ]
        },
        "source": {
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "c6f5cd8e-fe3d-4460-82c2-f8a4e7b272c8",
    "assignerShortName": "Vivo",
    "cveId": "CVE-2020-12483",
    "datePublished": "2021-03-23T16:15:00.995Z",
    "dateReserved": "2020-04-30T00:00:00.000Z",
    "dateUpdated": "2024-09-16T22:56:44.301Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}