CVE Vulnerabilities

CVE-2021-43512

Insecure Storage of Sensitive Information

Published: Jun 02, 2022 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Flightradar24_flight_tracker Flightradar24 8.9.0 (including) 8.9.0 (including)
Flightradar24_flight_tracker Flightradar24 8.10.0 (including) 8.10.0 (including)
Flightradar24_flight_tracker Flightradar24 8.10.2 (including) 8.10.2 (including)
Flightradar24_flight_tracker Flightradar24 8.10.3 (including) 8.10.3 (including)
Flightradar24_flight_tracker Flightradar24 8.10.4 (including) 8.10.4 (including)

References