CVE-2022-43451

HIGH

OpenHarmony <v3.1.2 - Path Traversal

Title source: llm
STIX 2.1

Description

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0019
EPSS Percentile 8.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22 CWE-287
Status published
Products (1)
openharmony/openharmony 3.1 - 3.1.2
Published Nov 03, 2022
Tracked Since Feb 18, 2026