CVE-2022-38117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
24/10/2022
Last modified:
25/10/2022

Description

Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:juiker:juiker:4.6.0311.1:*:*:*:*:android:*:*


References to Advisories, Solutions, and Tools