Path Traversal Vulnerability in computeValuesFromData of FileUtils.java Allows Unauthorized File Access

Path Traversal Vulnerability in computeValuesFromData of FileUtils.java Allows Unauthorized File Access

CVE-2023-35670 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Learn more about our External Network Penetration Testing.