CVE-2023-28387

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
30/06/2023
Last modified:
07/07/2023

Description

"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API key for an external service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uzabase:newspicks:*:*:*:*:*:iphone_os:*:* 10.4.2 (including)
cpe:2.3:a:uzabase:newspicks:*:*:*:*:*:android:*:* 10.4.5 (including)