CVE Vulnerabilities

CVE-2019-17398

Insertion of Sensitive Information into Log File

Published: Oct 15, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Dark_horse_comics Darkhorse 1.3.21 (including) 1.3.21 (including)

Potential Mitigations

References