Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r5h-7mq7-4q8v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.

In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.

EPSS

Процентиль: 45%
0.00222
Низкий

7.5 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.

EPSS

Процентиль: 45%
0.00222
Низкий

7.5 High

CVSS3

Дефекты

CWE-798