ZeroHour

CVE-2020-12624

PoC
CVSS 3.1
6.5 medium
EPSS
1%p69
Published
()
Modified
Description

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

Vendors
theleague
Products
the league
Weakness
CWE-459
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.