漏洞类型: 混淆的代理漏洞(Confused Deputy Vulnerability) 影响组件: termsActivity 修复措施: 仅当调用应用程序具有相应权限时,才能访问termsDisclaimer Uri 相关文档: go/termsDisclaimerVulnerability 变更前后的URL: - Before: https://hsv.googleplex.com/5163551739084800 - After: https://hsv.googleplex.com/5207829722955776, https://paste.googleplex.com/5643054726512640 标记: EXEMPT bug fix Bug编号: 299928772 测试方法: 使用报告者提供的测试应用程序手动测试 测试用例来源: - https://googleplex-android-review.googlesource.com/c/platform/packages/apps/ManagedProvisioning/+/216616ee588d6c00710fb2d3aab980 - https://googleplex-android-review.googlesource.com/c/platform/packages/apps/ManagedProvisioning/+/68ff8abc959c1a4f1803e8b5e04ee180aaa542992 合并到: I4c5ab4cc770c61db1ccd51l69a9b8cdcf8a4b0bd 更改ID: I4c5ab4cc770c61db1ccd51l69a9b8cdcf8a4b0bd 修改文件: src/com/android/managedprovisioning/parser/DisclaimersParserImpl.java