CVE-2024-32988

'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.
References
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-22 08:15

Updated : 2024-07-03 01:57


NVD link : CVE-2024-32988

Mitre link : CVE-2024-32988

CVE.ORG link : CVE-2024-32988


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials