Loading HuntDB...

GHSA-m5r4-qhx5-2g4c

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.getKey() could contain sensitive information. However, CarNotificationListener.java, it prints out the StatusBarNotification.getKey() directly in logs, which could contain user's account name (i.e. PII), in Android "user" build.Product: AndroidVersions: Android-12LAndroid ID: A-205567776

Related CVEs

Key Information

GHSA ID
GHSA-m5r4-qhx5-2g4c
Published
January 26, 2023 9:30 PM
Last Modified
February 1, 2023 3:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 20, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.