PT-2013-3648 · Fenrir · Sleipnir Mobile+1

Keita Haga

·

Published

2013-04-16

·

Updated

2013-04-16

·

CVE-2013-2304

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sleipnir Mobile application versions 2.8.0 and earlier Sleipnir Mobile Black Edition application versions 2.8.0 and earlier
Description The issue allows remote attackers to load arbitrary Extension APIs, and trigger downloads or obtain sensitive HTTP response-body information, via a crafted web page.
Recommendations For Sleipnir Mobile application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available. For Sleipnir Mobile Black Edition application versions 2.8.0 and earlier, consider restricting access to Extension APIs until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2304

Affected Products

Sleipnir Mobile
Sleipnir Mobile Black Edition