CVE-2024-20804: Path Traversal
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MyFiles (FileUriConverter)to a version that resolves this vulnerability.Fixed in SMR Jan-2024 Release 1 - Upgrade
Upgrade
MyFiles (FileUriConverter)to a version that resolves this vulnerability.Fixed in 14.5.00.21
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20804?
The severity of CVE-2024-20804 is classified as a critical vulnerability due to its potential for local attackers to write arbitrary files.
How do I fix CVE-2024-20804?
To fix CVE-2024-20804, update your Samsung device to the latest software release as specified in the January 2024 security updates.
Which versions of Android are affected by CVE-2024-20804?
CVE-2024-20804 affects Android versions 11, 12, and 13 prior to the January 2024 security update.
What impact does CVE-2024-20804 have on users?
CVE-2024-20804 allows attackers to exploit path traversal vulnerabilities, compromising the integrity of the device by potentially allowing unauthorized file access.
What products are impacted by CVE-2024-20804?
CVE-2024-20804 impacts Samsung's FileUriConverter within the MyFiles app on specific versions of Samsung Android devices.