Llouis.liuxumodify fix links
a47db3e4创建于 2022年10月27日历史提交

2022年6月安全漏洞

发布于2022.6.6
最后更新于2022.10.27

漏洞编号 相关漏洞 漏洞描述 漏洞影响 受影响的版本 受影响的仓库 修复链接 参考链接
OpenHarmony-SA-2022-0601 NA 事件通知子系统反序列化对象时会绕过认证机制。 攻击者可在本地发起攻击,造成权限绕过,导致服务端进程崩溃。 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.5-LTS
OpenHarmony-v3.1-Release
notification_common_event_service 3.0.x
3.1.x
本项目组上报
OpenHarmony-SA-2022-0602 NA 事件通知子系统存在校验绕过漏洞,可发起SA中继攻击。 攻击者可在本地发起攻击,造成校验绕过,获得系统控制权。 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS notification_common_event_service 3.0.x 本项目组上报
OpenHarmony-SA-2022-0603 NA 升级服务组件存在校验绕过漏洞,可发起SA中继攻击。 攻击者可在本地发起攻击,造成校验绕过,获得系统控制权。 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS update_updateservice 3.0.x 本项目组上报
OpenHarmony-SA-2022-0604 NA 多媒体子系统存在校验绕过漏洞,可发起SA中继攻击。 攻击者可在本地发起攻击,造成校验绕过,获取系统控制权。 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS multimedia_player_framework 3.0.x 本项目组上报

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE 严重程度 受影响的OpenHarmony版本 修复链接
CVE-2022-25313 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2022-25314 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2022-25315 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2022-25235 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2022-25236 严重 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2022-23308 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS 3.0.x
CVE-2022-25375 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-25258 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-0435 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-24959 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2021-44879 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-24958 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2021-45402 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2021-4160 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2022-0778 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-0886 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-1055 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-0995 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2021-39698 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-0494 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-1048 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-1016 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2021-39686 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-0500 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2022-28390 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-28389 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-28388 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-28893 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-1353 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-29156 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-28356 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x 暂未修复
CVE-2019-16089 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2021-4156 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-22576 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-27775 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-27776 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2022-27774 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS
OpenHarmony-v3.1-Release
3.0.x
3.1.x
CVE-2021-3520 严重 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS 3.0.x
CVE-2021-44732 严重 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2021-36690 OpenHarmony-v3.0-LTS和OpenHarmony-v3.0.1-LTS 3.0.x
CVE-2021-3732 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.3-LTS 3.0.x
CVE-2021-22570 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS 3.0.x
CVE-2021-22569 OpenHarmony-v3.0-LTS到OpenHarmony-v3.0.2-LTS 3.0.x