The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References
Link | Resource |
---|---|
https://itunes.apple.com/us/app/kinepasu-apuridekantan-bian/id637453055?mt=8 | Third Party Advisory |
https://jvn.jp/en/jp/JVN83671755/ | Third Party Advisory VDB Entry |
https://play.google.com/store/apps/details?id=jp.tjoy.kinepass&hl=en | Third Party Advisory |
https://itunes.apple.com/us/app/kinepasu-apuridekantan-bian/id637453055?mt=8 | Third Party Advisory |
https://jvn.jp/en/jp/JVN83671755/ | Third Party Advisory VDB Entry |
https://play.google.com/store/apps/details?id=jp.tjoy.kinepass&hl=en | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://itunes.apple.com/us/app/kinepasu-apuridekantan-bian/id637453055?mt=8 - Third Party Advisory | |
References | () https://jvn.jp/en/jp/JVN83671755/ - Third Party Advisory, VDB Entry | |
References | () https://play.google.com/store/apps/details?id=jp.tjoy.kinepass&hl=en - Third Party Advisory |
Information
Published : 2018-05-14 13:29
Updated : 2024-11-21 03:38
NVD link : CVE-2018-0591
Mitre link : CVE-2018-0591
CVE.ORG link : CVE-2018-0591
JSON object : View
Products Affected
t-joy
- kinepass
CWE
CWE-295
Improper Certificate Validation