PT-2024-28799 · Unknown · Life: Personal Diary
Published
2024-11-08
·
Updated
2024-11-13
·
CVE-2024-40239
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Life: Personal Diary, Journal android app version 17.5.0
Description
An issue with access control in the Life: Personal Diary, Journal android app allows a physically proximate attacker to escalate privileges via the fingerprint authentication function. This enables someone nearby to potentially exploit the flaw.
Recommendations
For version 17.5.0, consider disabling the fingerprint authentication function as a temporary workaround until a patch is available. Restrict access to sensitive features that rely on fingerprint authentication to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Life: Personal Diary