← Global Threat Landscape
CVE-2024-43093
CWE-176
Medium
67.2
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Source: NVD
Signals
- CVSS
- 7.3
- High · v3.1
- EPSS
- 0.70%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Nov 2024
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-176
- Published
- 13 Nov 2024
- Last modified 23 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-43093Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time