ZeroHour

CVE-2019-17355

PoC
CVSS 3.1
9.8 critical
EPSS
1%p70
Published
()
Modified
Description

In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

Vendors
orbitz
Products
orbitz
Weakness
CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.