Klapp App Authorization Credentials Bayani fitowa

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a Klapp App. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil $software_file, a cikin sashen Authorization. A sa manipulation ka Bayani fitowa (Credentials). Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-200. An gano matsalar a 08/18/2020. Hakika, rauni an bayyana shi 09/07/2020 daga Sven Fassbender tare da modzero AG kamar Knapp daneben ist auch vorbei kamar Gargaaji (Webseite). An raba bayanin tsaro don saukewa a modzero.com. Vendor an kaɗi, public release an kaɗi. Wannan matsala ana saninta da CVE-2020-36532. Ngam yiɗi ka a tuma ndiyam ka nder layi. Tekinikal faɗi ba ga. Babu exploit ɗin da ake samu. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu a wondi feere. 0-day shima, an ndiyam a wuro be $0-$5k. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a faggata. Once again VulDB remains the best source for vulnerability data.

3 Goyarwa · 54 Datenpunkte

FurɗeSúgá
09/07/2020 13:09
Gargadi 1/2
09/07/2020 14:03
Gargadi 2/2
06/03/2022 20:36
software_vendorKlappKlappKlapp
software_nameAppAppApp
software_componentAuthorizationAuthorizationAuthorization
vulnerability_discoverydate1597708800 (08/18/2020)1597708800 (08/18/2020)1597708800 (08/18/2020)
vulnerability_vendorinformdate1597795200 (08/19/2020)1597795200 (08/19/2020)1597795200 (08/19/2020)
vulnerability_risk111
vulnerability_historic000
cvss2_vuldb_basescore3.53.53.5
cvss2_vuldb_tempscore3.03.03.0
cvss2_vuldb_avNNN
cvss2_vuldb_acMMM
cvss2_vuldb_auSSS
cvss2_vuldb_ciPPP
cvss2_vuldb_iiNNN
cvss2_vuldb_aiNNN
cvss3_meta_basescore4.34.34.3
cvss3_meta_tempscore4.14.14.1
cvss3_vuldb_basescore4.34.34.3
cvss3_vuldb_tempscore4.14.14.1
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_prLLL
cvss3_vuldb_uiNNN
cvss3_vuldb_sUUU
cvss3_vuldb_cLLL
cvss3_vuldb_iNNN
cvss3_vuldb_aNNN
vulnerability_titlewordCredentialsCredentialsCredentials
advisory_date1599436800 (09/07/2020)1599436800 (09/07/2020)1599436800 (09/07/2020)
advisory_locationWebsiteWebsiteWebsite
advisory_typeAdvisoryAdvisoryAdvisory
advisory_urlhttps://www.modzero.com/modlog/archives/2020/09/07/knapp_daneben_ist_auch_vorbei/index.htmlhttps://www.modzero.com/modlog/archives/2020/09/07/knapp_daneben_ist_auch_vorbei/index.htmlhttps://www.modzero.com/modlog/archives/2020/09/07/knapp_daneben_ist_auch_vorbei/index.html
advisory_identifierKnapp daneben ist auch vorbeiKnapp daneben ist auch vorbeiKnapp daneben ist auch vorbei
advisory_coordination111
person_nameSven FassbenderSven FassbenderSven Fassbender
company_namemodzero AGmodzero AGmodzero AG
advisory_reaction_date1597968000 (08/21/2020)1597968000 (08/21/2020)1597968000 (08/21/2020)
advisory_disputed000
price_0day$0-$5k$0-$5k$0-$5k
countermeasure_nameGargajiyaGargajiyaGargajiya
countermeasure_date1598227200 (08/24/2020)1598227200 (08/24/2020)1598227200 (08/24/2020)
source_seealso160763160763160763
cvss2_vuldb_eNDNDND
cvss2_vuldb_rlOFOFOF
cvss2_vuldb_rcCCC
cvss3_vuldb_eXXX
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
reaction_days555
0day_days666
advisory_falsepositive00
vulnerability_cweCWE-200 (Bayani fitowa)CWE-200 (Bayani fitowa)
source_cveCVE-2020-36532
cna_responsibleVulDB

Do you want to use VulDB in your project?

Use the official API to access entries easily!