Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rhq-wwg6-2476

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).

The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).

EPSS

Процентиль: 7%
0.00028
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 4.1
nvd
больше 7 лет назад

The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android) or a plist file in the app data folder (on iOS).

EPSS

Процентиль: 7%
0.00028
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-312