CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AI Score
Confidence
Low
Improper verification of cryptographic signature issue exists in “FreeFrom - the nostr client” App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.
Vendor | Product | Version | CPE |
---|---|---|---|
freefrom_k.k. | \"freefrom_-_the_nostr_client\"_app_for_android | * | cpe:2.3:a:freefrom_k.k.:\"freefrom_-_the_nostr_client\"_app_for_android:*:*:*:*:*:*:*:* |
freefrom_k.k. | \"freefrom_-_the_nostr_client\"_app_for_ios | * | cpe:2.3:a:freefrom_k.k.:\"freefrom_-_the_nostr_client\"_app_for_ios:*:*:*:*:*:*:*:* |
[
{
"vendor": "FreeFrom K.K.",
"product": "\"FreeFrom - the nostr client\" App for Android",
"versions": [
{
"version": "prior to 1.3.5",
"status": "affected"
}
]
},
{
"vendor": "FreeFrom K.K.",
"product": "\"FreeFrom - the nostr client\" App for iOS",
"versions": [
{
"version": "prior to 1.3.5",
"status": "affected"
}
]
}
]