Vulnerability Description
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Google I\/O 2017 | <= 5.0.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/98549Third Party AdvisoryVDB Entry
- https://wwws.nightwatchcybersecurity.com/2017/05/17/advisory-google-io-2017-andrExploitThird Party Advisory
- http://www.securityfocus.com/bid/98549Third Party AdvisoryVDB Entry
- https://wwws.nightwatchcybersecurity.com/2017/05/17/advisory-google-io-2017-andrExploitThird Party Advisory
FAQ
What is CVE-2017-9045?
CVE-2017-9045 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof F...
How severe is CVE-2017-9045?
CVE-2017-9045 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9045?
Check the references section above for vendor advisories and patch information. Affected products include: Google Google I\/O 2017.