PT-2019-13606 · Bytedance · Tiktok

Publicado

2019-09-04

·

Atualizado

2020-08-24

·

CVE-2019-14319

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TikTok versions 12.2.0
Description The issue concerns the unencrypted transmission of sensitive data, including images, videos, and likes, over the network. This allows an attacker to extract private information by sniffing network traffic.
Recommendations For version 12.2.0, consider restricting network access to trusted environments until a fix is available, and avoid transmitting sensitive information over unsecured networks.

Exploit

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14319

Produtos afetados

Tiktok