Vulnerability Description
udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/en/cp-139-7893-43ecd-2.html
- https://www.twcert.org.tw/tw/cp-132-7892-aafd2-1.html
- https://www.twcert.org.tw/en/cp-139-7893-43ecd-2.html
- https://www.twcert.org.tw/tw/cp-132-7892-aafd2-1.html
FAQ
What is CVE-2024-6294?
CVE-2024-6294 is a vulnerability with a CVSS score of 3.9 (LOW). udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it t...
How severe is CVE-2024-6294?
CVE-2024-6294 has been rated LOW with a CVSS base score of 3.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6294?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.