QID 630752
Date Published: 2021-11-25
QID 630752: Nike App For Android Incorrect Authorization Vulnerability
Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions prior to 2.177.1 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-20834 to address this issue and obtain more information.
Vendor References
- CVE-2021-20834 -
nvd.nist.gov/vuln/detail/CVE-2021-20834
CVEs related to QID 630752
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-20834 | Android |
|