CVE Published: 22/05/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: i-plug inc. |
Product: \'OfferBox\' App for Android Status : PUBLISHED
CVE-2024-32988 Description
\'OfferBox\' App for Android versions 2.0.0 to 2.3.17 and \'OfferBox\' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.