202304月安全漏洞

发布于2023.04.04
最后更新于2023.04.04

以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。

CVE

严重程度

CVSS3.1

受影响的OpenHarmony版本

修复链接

CVE-2023-0597

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-30787

6.7

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.1

3.1.x

CVE-2015-20107

7.6

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release

3.1.x

CVE-2022-33068

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.1.1-LTS
OpenHarmony-v1.1.5-LTS

3.1.x
3.0.x
1.1.x

CVE-2022-4904

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-3594

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-22995

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-22999

5.0

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-26545

6.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-47929

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-2873

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23559

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1118

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1118

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-1652

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2021-3760

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2021-37576

7.8

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.8-LTS

3.0.x

CVE-2023-0461

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0461

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23455

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-26545

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-0480

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1076

4.7

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1073

6.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1074

4.7

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1078

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1095

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23000

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23002

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23004

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23006

8.4

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-26607

5.2

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0030

7.8

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23000

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1252

7.0

OpenHarmony-v3.0-LTSOpenHarmony-v3.0.8-LTS

3.0.x

CVE-2023-1390

7.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1078

5.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1074

4.7

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-28328

5.5

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0464

5.0

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1637

3.3

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0465

5.6

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0466

5.6

OpenHarmony-v3.1-ReleaseOpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS
OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

 

Security Vulnerabilities in April 2023

published April 4,2023
updated April 4,2023

The following table lists the third-party library vulnerabilities with only the CVE, severity, and affected OpenHarmony versions provided. For more details, see the security bulletins released by third-parties.

CVE

severity

CVSS3.1

affected OpenHarmony versions

fix link

CVE-2023-0597

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-30787

Medium

6.7

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.1

3.1.x

CVE-2015-20107

High

7.6

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release

3.1.x

CVE-2022-33068

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS
OpenHarmony-v1.1.1-LTS through OpenHarmony-v1.1.5-LTS

3.1.x
3.0.x
1.1.x

CVE-2022-4904

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-3594

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-22995

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-22999

Medium

5.0

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-26545

Medium

6.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-47929

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-2873

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23559

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1118

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1118

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-1652

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2021-3760

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2021-37576

High

7.8

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.0.x

CVE-2023-0461

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0461

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23455

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-26545

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2022-0480

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1076

Medium

4.7

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1073

Medium

6.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1074

Medium

4.7

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1078

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1095

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23000

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23002

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23004

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23006

High

8.4

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-26607

Medium

5.2

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0030

High

7.8

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.6-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-23000

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1252

High

7.0

OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.0.x

CVE-2023-1390

High

7.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1078

Medium

5.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1074

Medium

4.7

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-28328

Medium

5.5

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0464

Medium

5.0

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-1637

Low

3.3

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0465

Medium

5.6

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x

CVE-2023-0466

Medium

5.6

OpenHarmony-v3.1-Release through OpenHarmony-v3.1.7-Release
OpenHarmony-v3.0-LTS through OpenHarmony-v3.0.8-LTS

3.1.x
3.0.x