Description
'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN83405304/ |
|
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T02:27:53.227Z
Reserved: 2024-04-23T00:42:29.260Z
Link: CVE-2024-32988
Updated: 2024-08-02T02:27:53.227Z
Status : Deferred
Published: 2024-05-22T08:15:10.080
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-32988
No data.
OpenCVE Enrichment
No data.
Weaknesses