CVE Vulnerabilities

CVE-2024-27440

Improper Certificate Validation

Published: Mar 13, 2024 | Modified: Aug 05, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 dont properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References