PT-2019-13606 · Bytedance · Tiktok

Published

2019-09-04

·

Updated

2020-08-24

·

CVE-2019-14319

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TikTok versions 12.2.0
Description The issue concerns the unencrypted transmission of sensitive data, including images, videos, and likes, over the network. This allows an attacker to extract private information by sniffing network traffic.
Recommendations For version 12.2.0, consider restricting network access to trusted environments until a fix is available, and avoid transmitting sensitive information over unsecured networks.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14319

Affected Products

Tiktok