PT-2024-13160 · Line · Line

Published

2024-01-24

·

Updated

2024-01-27

·

CVE-2023-43996

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Line version 13.6.1
Description An issue in the Q co ltd mini-app on Line allows attackers to send crafted malicious notifications via leakage of the channel access token. This leakage enables attackers to exploit the system.
Recommendations For Line version 13.6.1, update to a newer version that addresses the leakage of the channel access token to prevent malicious notifications. As a temporary workaround, consider restricting access to the mini-app until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-43996

Affected Products

Line