Description

The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cryptographic algorithm known to allow hash collisions. This makes the authentication mechanism vulnerable to replay, spoofing, or brute-force attacks, potentially leading to unauthorized access. The vulnerability corresponds to CWE-327 and aligns with OWASP M5: Insufficient Cryptography and MASVS MSTG-CRYPTO-4.

INFO

Published Date :

2025-09-03T00:00:00.000Z

Last Modified :

2025-09-03T19:09:03.703Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-56608 vulnerability.

Vendors Products
Donbermoy
  • Android Corona Virus Tracker App For India
Google
  • Android
Sourcecodester
  • Corona Virus Tracker App India

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact