Lucene search

K
jvnJapan Vulnerability NotesJVN:84642320
HistoryJan 31, 2023 - 12:00 a.m.

JVN#84642320: SUSHIRO App for Android outputs sensitive information to the log file

2023-01-3100:00:00
Japan Vulnerability Notes
jvn.jp
14
sushiro app
android
sensitive information
log file
cwe-532
update
akindo sushiro co.
ltd.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

55.3%

SUSHIRO App for Android provided by AKINDO SUSHIRO CO., LTD. outputs sensitive information to the log file (CWE-532).

Impact

An attacker may obtain a credential information from the log file.

Solution

Update the Application
Update the application to the latest version according to the information provided by the developer.
The developer has released the following versions to fix the vulnerability.

  • SUSHIRO Ver.4.0.32
  • Thailand SUSHIRO Ver.2.0.3
  • Hong Kong SUSHIRO Ver.3.0.3
  • Singapore SUSHIRO Ver.2.0.3
  • Taiwan SUSHIRO Ver.2.0.3

Products Affected

  • SUSHIRO Ver.4.0.31
  • Thailand SUSHIRO Ver.1.0.0
  • Hong Kong SUSHIRO Ver.3.0.2
  • Singapore SUSHIRO Ver.2.0.0
  • Taiwan SUSHIRO Ver.2.0.1

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

55.3%

Related for JVN:84642320