MEDIUM
Session 1.17.5 - LFR via chat attachment
Published Feb 29, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.33%
Description
Session version 1.17.5 allows obtaining internal application files and public
files from the user's device without the user's consent. This is possible
because the application is vulnerable to Local File Read via chat attachments.
Affected products
-
- Version 1.17.5StatusaffectedConstraints-
- Version
-
- Version 1.17.5StatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27011 Advisory
- https://fluidattacks.com/advisories/newman/ ExploitThird Party Advisory
- https://github.com/oxen-io/session-android/ Product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27011 | Advisory | |
| https://fluidattacks.com/advisories/newman/ | ExploitThird Party Advisory | |
| https://github.com/oxen-io/session-android/ | Product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Feb 29, 2024
Updated May 19, 2025
Reserved Feb 29, 2024
Link CVE-2024-2045
CISA Vulnrichment
Updated Mar 6, 2024
ENISA EUVD
EUVD-2024-27011 Assigner Fluid Attacks
Published Feb 29, 2024
Updated May 19, 2025
Exploited since n/a
Link EUVD-2024-27011