CVE-2019-14319

The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network traffic.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:tiktok:tiktok:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.3.0:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.4.0:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.6.0:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.6.1:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.7.0:*:*:*:*:*:*:*
cpe:2.3:a:tiktok:tiktok:12.8.0:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:26

Type Values Removed Values Added
References () http://p16.muscdn.com/img/musically-maliva-obj/1626792871331845~c5_100x100.jpeg - Not Applicable () http://p16.muscdn.com/img/musically-maliva-obj/1626792871331845~c5_100x100.jpeg - Not Applicable
References () http://p16.muscdn.com/img/tos-maliva-p-0068/d9e7889f4f2d43028b41947cb0950c32~noop.image - Not Applicable () http://p16.muscdn.com/img/tos-maliva-p-0068/d9e7889f4f2d43028b41947cb0950c32~noop.image - Not Applicable
References () https://github.com/MelroyB/CVE-2019-14319/blob/master/CVE%202019-14319%20.pdf - Third Party Advisory () https://github.com/MelroyB/CVE-2019-14319/blob/master/CVE%202019-14319%20.pdf - Third Party Advisory
References () https://play.google.com/store/apps/details?id=com.zhiliaoapp.musically&hl=en_US - Product () https://play.google.com/store/apps/details?id=com.zhiliaoapp.musically&hl=en_US - Product

Information

Published : 2019-09-04 20:15

Updated : 2024-11-21 04:26


NVD link : CVE-2019-14319

Mitre link : CVE-2019-14319

CVE.ORG link : CVE-2019-14319


JSON object : View

Products Affected

apple

  • iphone_os

tiktok

  • tiktok

google

  • android
CWE
CWE-319

Cleartext Transmission of Sensitive Information