Description
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 12 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-798 | |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-11-12T17:15:57.289Z
Reserved: 2024-06-18T01:36:52.664Z
Link: CVE-2024-38480
Updated: 2024-08-02T04:12:24.715Z
Status : Deferred
Published: 2024-07-01T05:15:04.613
Modified: 2026-06-17T07:40:22.020
Link: CVE-2024-38480
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-798
Use of Hard-coded Credentials