CVE-2019-17398
Summary
| CVE | CVE-2019-17398 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-15 21:15:00 UTC |
| Updated | 2019-10-17 13:32:00 UTC |
| Description | In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat. |
Risk And Classification
Problem Types: CWE-532
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Darkhorse | Dark Horse Comics | 1.3.21 | All | All | All |
| Application | Darkhorse | Dark Horse Comics | 1.3.21 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Vulnerability in Dark Horse Comics - Logging Sensit - Pastebin.com | MISC | pastebin.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.