PT-2021-14202 · Retty · Retty App For Android+1

Ryo Sato

·

Published

2021-07-14

·

Updated

2021-07-15

·

CVE-2021-20747

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Retty App for Android versions prior to 4.8.13 Retty App for iOS versions prior to 4.11.14
Description: The issue is related to improper authorization in the handler for a custom URL scheme, allowing a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
Recommendations: For Retty App for Android versions prior to 4.8.13, update to version 4.8.13 or later. For Retty App for iOS versions prior to 4.11.14, update to version 4.11.14 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20747

Affected Products

Retty App For Android
Retty App For Ios