CVE-2022-43449: Arbitrary file read via download_server.
OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via downloadserver. Local attackers can install an malicious application on the device and reveal any file from the filesystem that is accessible to downloadserver service which run with UID 1000.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenHarmonyto a version that resolves this vulnerability.Fixed in 3.1.2
Event History
Frequently Asked Questions
What is CVE-2022-43449?
CVE-2022-43449 is an arbitrary file read vulnerability in OpenHarmony-v3.1.2 and prior versions via the download_server service.
What is the severity of CVE-2022-43449?
CVE-2022-43449 has a severity rating of 5.5, which is considered medium.
How does CVE-2022-43449 affect OpenHarmony?
CVE-2022-43449 allows local attackers to install a malicious application on the device and access files from the filesystem that are accessible to the download_server service.
How can I mitigate CVE-2022-43449?
To mitigate CVE-2022-43449, it is recommended to update OpenHarmony to version 3.1.2 or later.
Where can I find more information about CVE-2022-43449?
More information about CVE-2022-43449 can be found at the following reference: [link](https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-11.md)