cvelist/2024/54xxx/CVE-2024-54014.json
2024-12-05 03:00:34 +00:00

95 lines
3.5 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-54014",
"ASSIGNER": "vultures@jpcert.or.jp",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Improper authorization in handler for custom URL scheme",
"cweId": "CWE-939"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "SKYLARK HOLDINGS CO., LTD.",
"product": {
"product_data": [
{
"product_name": "'Skylark' App for Android",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "6.2.13 and earlier"
}
]
}
},
{
"product_name": "'Skylark' App for iOS",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "6.2.13 and earlier"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://play.google.com/store/apps/details?id=jp.co.skylark.app.gusto",
"refsource": "MISC",
"name": "https://play.google.com/store/apps/details?id=jp.co.skylark.app.gusto"
},
{
"url": "https://apps.apple.com/jp/app/%E3%81%99%E3%81%8B%E3%81%84%E3%82%89%E3%83%BC%E3%81%8F%E3%82%A2%E3%83%97%E3%83%AA/id906930478",
"refsource": "MISC",
"name": "https://apps.apple.com/jp/app/%E3%81%99%E3%81%8B%E3%81%84%E3%82%89%E3%83%BC%E3%81%8F%E3%82%A2%E3%83%97%E3%83%AA/id906930478"
},
{
"url": "https://jvn.jp/en/jp/JVN03447226/",
"refsource": "MISC",
"name": "https://jvn.jp/en/jp/JVN03447226/"
}
]
},
"impact": {
"cvss": [
{
"version": "3.0",
"baseSeverity": "LOW",
"baseScore": 3.6,
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
]
}
}