SB2023031760 - openEuler 22.03 LTS SP1 update for epiphany



SB2023031760 - openEuler 22.03 LTS SP1 update for epiphany

Published: March 17, 2023

Security Bulletin ID SB2023031760
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Exposure of Resource to Wrong Sphere (CVE-ID: CVE-2023-26081)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error in the autofill feature. A remote attacker can trick users into exfiltrating passwords due to autofill occurs in sandboxed contexts.


Remediation

Install update from vendor's website.