CVE-2022-39043

Juiker app stores debug logs which contains sensitive information to mobile external storage. An unauthenticated physical attacker can access these files to acquire partial user information such as personal contacts.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6922-4a37a-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:juiker:juiker:4.6.0607.1:*:*:*:*:android:*:*

History

21 Jul 2023, 20:33

Type Values Removed Values Added
CWE NVD-CWE-noinfo CWE-532
CWE-922

01 Apr 2023, 01:42

Type Values Removed Values Added
First Time Juiker
Juiker juiker
CPE cpe:2.3:a:juiker:juiker:4.6.0607.1:*:*:*:*:android:*:*
References (CONFIRM) https://www.twcert.org.tw/tw/cp-132-6922-4a37a-1.html - (CONFIRM) https://www.twcert.org.tw/tw/cp-132-6922-4a37a-1.html - Third Party Advisory
CWE CWE-200 NVD-CWE-noinfo

27 Mar 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-27 04:15

Updated : 2023-12-10 15:01


NVD link : CVE-2022-39043

Mitre link : CVE-2022-39043

CVE.ORG link : CVE-2022-39043


JSON object : View

Products Affected

juiker

  • juiker
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-922

Insecure Storage of Sensitive Information

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor