PT-2023-22284 · Unknown · Jiyu Kukan Toku-Toku Coupon App
Ryo Nihonyanagi
·
Publicado
2023-06-13
·
Atualizado
2023-06-23
·
CVE-2023-29501
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier
Jiyu Kukan Toku-Toku coupon App for Android versions 3.5.0 and earlier
Description
The issue is related to improper server certificate verification. If exploited, it may allow a man-in-the-middle attack, enabling an attacker to eavesdrop on encrypted communication.
Recommendations
For Jiyu Kukan Toku-Toku coupon App for iOS versions 3.5.0 and earlier, update to a version later than 3.5.0 to resolve the issue.
For Jiyu Kukan Toku-Toku coupon App for Android versions 3.5.0 and earlier, update to a version later than 3.5.0 to resolve the issue.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jiyu Kukan Toku-Toku Coupon App