CVE-2024-6294

Published Jun 25, 2024

Last updated 5 months ago

Overview

Description
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
Source
twcert@cert.org.tw
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
3.9
Impact score
3.6
Exploitability score
0.3
Vector string
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Severity
LOW

Weaknesses

twcert@cert.org.tw
CWE-200

Social media

Hype score
Not currently trending