25 lines
1.1 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-45240",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-08-24T23:15:04.407",
"lastModified": "2024-08-26T12:47:20.187",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On Android 12 and later, this is only exploitable by third-party applications.)"
},
{
"lang": "es",
"value": "La aplicaci\u00f3n TikTok (tambi\u00e9n conocida como com.zhiliaoapp.musically) anterior a 34.5.5 para Android permite la toma de control de las interfaces JavaScript de Lynxview a trav\u00e9s del cruce de enlaces profundos (en el WebView expuesto de la aplicaci\u00f3n). (En Android 12 y versiones posteriores, esto solo es aprovechable por aplicaciones de terceros)."
}
],
"metrics": {},
"references": [
{
"url": "https://hackerone.com/reports/2417516",
"source": "cve@mitre.org"
}
]
}