Description
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
No analysis available yet.
Remediation
Vendor Solution
Updated to version 4.20.1 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47412 | udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-08-01T21:33:05.316Z
Reserved: 2024-06-25T01:39:06.351Z
Link: CVE-2024-6294
Updated: 2024-08-01T21:33:05.316Z
Status : Deferred
Published: 2024-06-25T02:15:11.657
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-6294
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD