udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: twcert

Published: 2024-06-25T02:13:44.379Z

Updated: 2024-06-25T20:38:40.726Z

Reserved: 2024-06-25T01:39:09.389Z


Link: CVE-2024-6295

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-25T03:15:10.740

Modified: 2024-06-25T12:24:17.873


Link: CVE-2024-6295

JSON object: View

cve-icon Redhat Information

No data.

CWE