CVE Vulnerabilities

CVE-2024-36279

Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking

Published: Jun 17, 2024 | Modified: Jul 03, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in FreeFrom - the nostr client App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.

Weakness

The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified.

Potential Mitigations

References