Description
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
INFO
Published Date :
2024-06-25T02:13:44.379Z
Last Modified :
2024-08-01T21:33:05.390Z
Source :
twcert
AFFECTED PRODUCTS
The following products are affected by CVE-2024-6295 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-6295.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact