udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: twcert
Published: 2024-06-25T02:13:44.379Z
Updated: 2024-08-01T21:33:05.390Z
Reserved: 2024-06-25T01:39:09.389Z
Link: CVE-2024-6295

Updated: 2024-08-01T21:33:05.390Z

Status : Awaiting Analysis
Published: 2024-06-25T03:15:10.740
Modified: 2024-11-21T09:49:22.777
Link: CVE-2024-6295

No data.