udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-06-25T02:13:44.379Z
Updated: 2024-08-01T21:33:05.390Z
Reserved: 2024-06-25T01:39:09.389Z
Link: CVE-2024-6295
Vulnrichment
Updated: 2024-08-01T21:33:05.390Z
NVD
Status : Awaiting Analysis
Published: 2024-06-25T03:15:10.740
Modified: 2024-06-25T12:24:17.873
Link: CVE-2024-6295
Redhat
No data.