Description
'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.
INFO
Published Date :
2024-05-22T07:37:32.362Z
Last Modified :
2024-08-02T02:27:53.227Z
Source :
jpcert
AFFECTED PRODUCTS
The following products are affected by CVE-2024-32988 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-32988.
| URL | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN83405304/ |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact