'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jvn.jp/en/jp/JVN83405304/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-05-22T07:37:32.362Z
Updated: 2024-08-02T02:27:53.227Z
Reserved: 2024-04-23T00:42:29.260Z
Link: CVE-2024-32988
Vulnrichment
Updated: 2024-08-02T02:27:53.227Z
NVD
Status : Awaiting Analysis
Published: 2024-05-22T08:15:10.080
Modified: 2024-11-21T09:16:10.737
Link: CVE-2024-32988
Redhat
No data.