CVE-2023-46100: Cert manager has a use of uninitialized resource vulnerability
in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-46100.
What is the title of the vulnerability?
The title of the vulnerability is Cert manager has a use of uninitialized resource vulnerability.
What is the description of the vulnerability?
The vulnerability allows a local attacker to get sensitive buffer information through the use of an uninitialized resource in OpenHarmony v3.2.2 and prior versions.
What software versions are affected by the vulnerability?
The vulnerability affects OpenHarmony v3.2.2 and prior versions.
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS v3.1 base score of 6.2.
How can the vulnerability be fixed?
The vulnerability can be fixed by updating to a version of OpenHarmony that is not affected by the issue.
Where can I find more information about the vulnerability?
More information about the vulnerability can be found at the following URL: https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2023/2023-12.md