Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-288h-h8hx-vvqm

Опубликовано: 24 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

EPSS

Процентиль: 13%
0.00046
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

EPSS

Процентиль: 13%
0.00046
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-798