Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fpw-6gvj-w9xf

Опубликовано: 22 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

EPSS

Процентиль: 54%
0.00317
Низкий

7.5 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

EPSS

Процентиль: 54%
0.00317
Низкий

7.5 High

CVSS3

Дефекты

CWE-798