Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ff7f-3f4v-gpgc

Опубликовано: 03 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 1

Описание

In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the last application view displayed before the application was minimized

This issue was fixed in version 4.71.0

In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the last application view displayed before the application was minimized

This issue was fixed in version 4.71.0

EPSS

Процентиль: 4%
0.00018
Низкий

1 Low

CVSS4

Дефекты

CWE-359

Связанные уязвимости

nvd
5 дней назад

In mObywatel iOS application an unauthorized user can use the App Switcher to view the account owner's personal information in the minimized app window, even after the login session has ended (reopening the app would require the user to log in). The data exposed depends on the last application view displayed before the application was minimized This issue was fixed in version 4.71.0

EPSS

Процентиль: 4%
0.00018
Низкий

1 Low

CVSS4

Дефекты

CWE-359