PT-2018-5479 · Uber · Ubereats
Published
2018-08-15
·
Updated
2019-10-09
·
CVE-2017-13104
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
UberEATS version 1.108.10001
Description:
The issue concerns the use of a hard-coded key for encryption in the iOS application. This means that data stored using this key can be decrypted by anyone who can access the key.
Recommendations:
For version 1.108.10001, consider disabling the encryption feature that uses the hard-coded key until a patch is available that replaces the hard-coded key with a secure encryption method. Restrict access to sensitive data stored by the application to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubereats