CVE-2024-22092: Bundlemanager has an authentication bypass vulnerability
Published Apr 2, 2024
·Updated
in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.
Affected Software
2 affected components
OpenHarmony OpenHarmony<3.2.4
Openatom Openharmony>=3.2<=3.2.4
Event History
Apr 2, 2024
CVE Published
via MITRE·06:22 AM
Data Sourced
via MITRE·06:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-22092?
CVE-2024-22092 has a medium severity rating due to its ability to allow remote attackers to bypass permission verification.
2
How do I fix CVE-2024-22092?
To fix CVE-2024-22092, update OpenHarmony to a version later than v3.2.4.
3
Who is affected by CVE-2024-22092?
CVE-2024-22092 affects users of OpenHarmony versions v3.2.4 and earlier.
4
What kind of attack is possible with CVE-2024-22092?
CVE-2024-22092 allows a remote attacker to bypass permission verification for app installations, requiring user interaction.
5
When was CVE-2024-22092 disclosed?
CVE-2024-22092 was disclosed in April 2024.