Логотип exploitDog
bind:CVE-2020-12624
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-12624

Количество 2

Количество 2

nvd логотип

CVE-2020-12624

почти 6 лет назад

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-44cp-gcp7-fxgm

больше 3 лет назад

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-12624

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
github логотип
GHSA-44cp-gcp7-fxgm

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу