PT-2024-13162 · Line · Line

Published

2024-01-24

·

Updated

2024-09-03

·

CVE-2023-43998

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Line version 13.6.1
Description An issue in the Books-futaba mini-app on Line allows attackers to send crafted malicious notifications via leakage of the channel access token. This leakage enables attackers to exploit the system, potentially leading to unauthorized access or malicious activities.
Recommendations For Line version 13.6.1, update to a newer version that addresses the issue of the channel access token leakage to prevent attackers from sending crafted malicious notifications.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-43998

Affected Products

Line