JVN#83405304: “OfferBox” App uses a hard-coded secret key
Discription
"OfferBox" App provided by i-plug inc. uses a hard-coded secret key for JWT (CWE-321). ## Impact The hard-coded secret key for JWT may be retrieved if the application binary is reverse-engineered. ## Solution The hard-coded secret key has been revoked by the developer on May 8, 2024 therefore this vulnerability is not exploitable. The developer has released the following updates which do not contain hard-coded secret keys: "OfferBox" App for Android 3.0.0 "OfferBox" App for iOS 3.0.0 ## Products Affected "OfferBox" App for Android 2.0.0 to 2.3.17 "OfferBox" App for iOS 2.1.7 to…Read More
References
Back to Main