PT-2021-14202 · Retty · Retty App For Android+1
Ryo Sato
·
Published
2021-07-14
·
Updated
2021-07-15
·
CVE-2021-20747
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Retty App for Android versions prior to 4.8.13
Retty App for iOS versions prior to 4.11.14
Description:
The issue is related to improper authorization in the handler for a custom URL scheme, allowing a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
Recommendations:
For Retty App for Android versions prior to 4.8.13, update to version 4.8.13 or later.
For Retty App for iOS versions prior to 4.11.14, update to version 4.11.14 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Retty App For Android
Retty App For Ios