Ichiran App for iOS versions prior to 3.1.0 and Ichiran App for Android versions prior to 3.1.0 improperly verify server certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.
                
            References
                    | Link | Resource | 
|---|---|
| https://play.google.com/store/apps/details?id=jp.co.ichiran.app&hl=ja | Product | 
| https://apps.apple.com/jp/app/%E4%B8%80%E8%98%AD%E5%85%AC%E5%BC%8F%E3%82%A2%E3%83%97%E3%83%AA/id1118806170 | Product | 
| https://jvn.jp/en/jp/JVN11257333/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2023-02-12 18:21
Updated : 2023-02-23 22:29
NVD link : CVE-2023-22367
Mitre link : CVE-2023-22367
JSON object : View
CWE
                
                    
                        
                        CWE-295
                        
            Improper Certificate Validation
Products Affected
                ichiranusa
- ichiran


