The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN83671755/ | Third Party Advisory VDB Entry |
https://itunes.apple.com/us/app/kinepasu-apuridekantan-bian/id637453055?mt=8 | Third Party Advisory |
https://play.google.com/store/apps/details?id=jp.tjoy.kinepass&hl=en | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-05-14 06:29
Updated : 2018-06-25 10:00
NVD link : CVE-2018-0591
Mitre link : CVE-2018-0591
JSON object : View
CWE
CWE-295
Improper Certificate Validation
Products Affected
t-joy
- kinepass