CVE-2023-21265
Summary
| CVE | CVE-2023-21265 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-14 21:15:00 UTC |
| Updated | 2023-08-24 15:09:00 UTC |
| Description | In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 6065b4a4c7da9cc9ee01c2f6389575647d2724c4 - platform/system/ca-certificates - Git at Google | MISC | android.googlesource.com | |
| Android Security Bulletin—August 2023 | Android Open Source Project | MISC | source.android.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.