PT-2018-5479 · Uber · Ubereats

Published

2018-08-15

·

Updated

2019-10-09

·

CVE-2017-13104

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: UberEATS version 1.108.10001
Description: The issue concerns the use of a hard-coded key for encryption in the iOS application. This means that data stored using this key can be decrypted by anyone who can access the key.
Recommendations: For version 1.108.10001, consider disabling the encryption feature that uses the hard-coded key until a patch is available that replaces the hard-coded key with a secure encryption method. Restrict access to sensitive data stored by the application to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13104

Affected Products

Ubereats