{ "schema_version": "1.4.0", "id": "GHSA-qj8f-q4w4-3qfp", "modified": "2024-04-04T01:20:38Z", "published": "2022-05-24T16:50:56Z", "aliases": [ "CVE-2019-1010221" ], "details": "LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` can also be set in a normal adb shell session. The component is: adb shell (patches to fix this are at https://review.lineageos.org/c/LineageOS/android_system_core/+/234800, https://review.lineageos.org/c/LineageOS/android_device_lineage_sepolicy/+/234799). The attack vector is: When adb is enabled, and an attacker has physical access, `adb shell setprop service.adb.root 1` allows restarting adb as root.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-1010221" }, { "type": "WEB", "url": "https://gist.github.com/zifnab06/e31ad63596b63a95e061bfe1f49ff0a7" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-07-23T14:15:00Z" } }