| [Japanese] | |
JVNDB-2024-000045 | |
"OfferBox" App uses a hard-coded secret key | |
| Overview | |
"OfferBox" App provided by i-plug inc. uses a hard-coded secret key for JWT (CWE-321). | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V3 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
| |
| Affected Products | |
|
| |
i-plug,inc. | |
|
| |
| Impact | |
The hard-coded secret key for JWT may be retrieved if the application binary is reverse-engineered. | |
| Solution | |
The hard-coded secret key has been revoked by the developer on May 8, 2024 therefore this vulnerability is not exploitable. | |
| Vendor Information | |
i-plug,inc. | |
| CWE (What is CWE?) | |
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2024/05/10 |
| Date First Published | 2024/05/10 |
| Date Last Updated | 2024/05/10 |


