Description

The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious document providers. This may result in cases where a user with a malicious document provider installed can select an image file from that provider while using your app and could potentially override internal files in your app cache. Issue patched in 0.8.12+18. It is recommended to update to the latest version of image_picker_android that contains the changes to address this vulnerability.

INFO

Published Date :

2025-01-29T11:52:05.386Z

Last Modified :

2025-02-12T19:51:14.154Z

Source :

Google
AFFECTED PRODUCTS

The following products are affected by CVE-2024-54462 vulnerability.

Vendors Products
Flutter
  • Image Picker Android
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-54462.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact