Vulnerability Description
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Last.Fm | Last.Fm Desktop | <= 2.1.39 |
Related Weaknesses (CWE)
References
- https://getsatisfaction.com/lastfm/topics/why-doesnt-the-macos-client-enable-sslThird Party Advisory
- https://getsatisfaction.com/lastfm/topics/why-doesnt-the-macos-client-enable-sslThird Party Advisory
FAQ
What is CVE-2019-19251?
CVE-2019-19251 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by de...
How severe is CVE-2019-19251?
CVE-2019-19251 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19251?
Check the references section above for vendor advisories and patch information. Affected products include: Last.Fm Last.Fm Desktop.