First published: Fri Sep 09 2022(Updated: )
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | >=3.1<=3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38064 is a permission bypass vulnerability in OpenHarmony-v3.1.2 and prior versions.
CVE-2022-38064 allows local attackers to bypass permission control and access sensitive information.
The severity of CVE-2022-38064 is medium with a score of 5.5.
To fix CVE-2022-38064, update OpenHarmony to version 3.1.2 or later.
More information about CVE-2022-38064 can be found at the following reference: [CVE-2022-38064](https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md).