CVE-2019-14319
Summary
| CVE | CVE-2019-14319 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-04 20:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network traffic. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | - | All | All | All |
| Operating System | Apple | Iphone Os | - | All | All | All |
| Operating System | Android | - | All | All | All | |
| Operating System | Android | - | All | All | All | |
| Application | Tiktok | Tiktok | 12.2.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.3.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.4.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.5.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.6.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.6.1 | All | All | All |
| Application | Tiktok | Tiktok | 12.7.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.8.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.2.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.3.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.4.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.5.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.6.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.6.1 | All | All | All |
| Application | Tiktok | Tiktok | 12.7.0 | All | All | All |
| Application | Tiktok | Tiktok | 12.8.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-14319/CVE 2019-14319 .pdf at master · MelroyB/CVE-2019-14319 · GitHub | MISC | github.com | Third Party Advisory |
| p16.muscdn.com/img/tos-maliva-p-0068/d9e7889f4f2d43028b41947cb0950c32~noop.i... | MISC | p16.muscdn.com | Not Applicable |
| p16.muscdn.com/img/musically-maliva-obj/1626792871331845~c5_100x100.jpeg | MISC | p16.muscdn.com | Not Applicable |
| TikTok - Apps on Google Play | MISC | play.google.com | Product |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.