{"api_version":"1","generated_at":"2026-07-23T10:59:42+00:00","cve":"CVE-2019-17398","urls":{"html":"https://cve.report/CVE-2019-17398","api":"https://cve.report/api/cve/CVE-2019-17398.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-17398","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-17398"},"summary":{"title":"CVE-2019-17398","description":"In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-10-15 21:15:00","updated_at":"2019-10-17 13:32:00"},"problem_types":["CWE-532"],"metrics":[],"references":[{"url":"https://pastebin.com/5ZDDCqgL","name":"https://pastebin.com/5ZDDCqgL","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Security Vulnerability in Dark Horse Comics - Logging Sensit - Pastebin.com","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-17398","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17398","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"17398","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"darkhorse","cpe5":"dark_horse_comics","cpe6":"1.3.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"17398","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"darkhorse","cpe5":"dark_horse_comics","cpe6":"1.3.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-17398","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://pastebin.com/5ZDDCqgL","refsource":"MISC","name":"https://pastebin.com/5ZDDCqgL"}]}},"nvd":{"publishedDate":"2019-10-15 21:15:00","lastModifiedDate":"2019-10-17 13:32:00","problem_types":["CWE-532"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:darkhorse:dark_horse_comics:1.3.21:*:*:*:*:android:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"17398","Ordinal":"157178","Title":"CVE-2019-17398","CVE":"CVE-2019-17398","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"17398","Ordinal":"1","NoteData":"In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"17398","Ordinal":"2","NoteData":"2019-10-15","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"17398","Ordinal":"3","NoteData":"2019-10-15","Type":"Other","Title":"Modified"}]}}}