Описание
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary.
Ссылки
- Third Party Advisory
- Product
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 4.28.0 (исключая)
cpe:2.3:a:wolt:wolt_delivery:*:*:*:*:*:android:*:*
EPSS
Процентиль: 10%
0.00035
Низкий
7.8 High
CVSS3
Дефекты
CWE-798
CWE-798
Связанные уязвимости
CVSS3: 7.8
github
почти 3 года назад
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary.
EPSS
Процентиль: 10%
0.00035
Низкий
7.8 High
CVSS3
Дефекты
CWE-798
CWE-798