PT-2019-13606 · Bytedance · Tiktok
Publicado
2019-09-04
·
Atualizado
2020-08-24
·
CVE-2019-14319
CVSS v3.1
6.5
Média
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TikTok versions 12.2.0
Description
The issue concerns the unencrypted transmission of sensitive data, including images, videos, and likes, over the network. This allows an attacker to extract private information by sniffing network traffic.
Recommendations
For version 12.2.0, consider restricting network access to trusted environments until a fix is available, and avoid transmitting sensitive information over unsecured networks.
Exploit
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tiktok