Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6r2w-57p9-f5hh

Опубликовано: 23 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information.

The Planet Fitness Workouts iOS and Android mobile apps prior to version 9.8.12 (released on 2024-07-25) fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information.

EPSS

Процентиль: 27%
0.00094
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in version 9.9.13 (released on 2025-02-11).

EPSS

Процентиль: 27%
0.00094
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-295