[Japanese] | |
JVNDB-2024-000045 | |
"OfferBox" App uses a hard-coded secret key | |
Overview | |
"OfferBox" App provided by i-plug inc. uses a hard-coded secret key for JWT (CWE-321). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
| |
Affected Products | |
| |
i-plug,inc. | |
| |
Impact | |
The hard-coded secret key for JWT may be retrieved if the application binary is reverse-engineered. | |
Solution | |
The hard-coded secret key has been revoked by the developer on May 8, 2024 therefore this vulnerability is not exploitable. | |
Vendor Information | |
i-plug,inc. | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/05/10 |
Date First Published | 2024/05/10 |
Date Last Updated | 2024/05/10 |