'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the user's device. As a result, the user may be redirected to an unauthorized site, and the user may become a victim of a phishing attack.
History

Fri, 30 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
CPEs cpe:2.3:a:rakuten:ichiba:*:*:*:*:*:android:*:*
cpe:2.3:a:rakuten:ichiba:*:*:*:*:*:iphone_os:*:*

Fri, 30 Aug 2024 00:30:00 +0000


Fri, 30 Aug 2024 00:00:00 +0000

Type Values Removed Values Added
References

Thu, 29 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Rakuten
Rakuten ichiba
Weaknesses CWE-939
CPEs cpe:2.3:a:rakuten:ichiba:*:*:*:*:*:*:*:*
Vendors & Products Rakuten
Rakuten ichiba
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Aug 2024 03:00:00 +0000

Type Values Removed Values Added
Description 'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the user's device. As a result, the user may be redirected to an unauthorized site, and the user may become a victim of a phishing attack.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2024-08-29T02:47:19.480Z

Updated: 2024-08-29T23:58:41.985Z

Reserved: 2024-07-25T00:40:40.647Z

Link: CVE-2024-41918

cve-icon Vulnrichment

Updated: 2024-08-29T13:48:37.440Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-29T03:15:05.130

Modified: 2024-08-30T16:05:23.737

Link: CVE-2024-41918

cve-icon Redhat

No data.