PT-2019-13606 · Bytedance · Tiktok
Published
2019-09-04
·
Updated
2020-08-24
·
CVE-2019-14319
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TikTok versions 12.2.0
Description
The issue concerns the unencrypted transmission of sensitive data, including images, videos, and likes, over the network. This allows an attacker to extract private information by sniffing network traffic.
Recommendations
For version 12.2.0, consider restricting network access to trusted environments until a fix is available, and avoid transmitting sensitive information over unsecured networks.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tiktok