CVE-2023-5554

Lack of TLS certificate verification in log transmission of a financial module within LINE Client for iOS prior to 13.16.0.
References
Link Resource
https://hackerone.com/reports/2106827 Permissions Required
Configurations

Configuration 1 (hide)

cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*

History

17 Oct 2023, 15:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Linecorp line
Linecorp
CWE CWE-295
CPE cpe:2.3:a:linecorp:line:*:*:*:*:*:iphone_os:*:*
References (MISC) https://hackerone.com/reports/2106827 - (MISC) https://hackerone.com/reports/2106827 - Permissions Required

12 Oct 2023, 12:59

Type Values Removed Values Added
Summary Lack of TLS certificate verification in log transmission of a financial module within LINE prior to 13.16.0. Lack of TLS certificate verification in log transmission of a financial module within LINE Client for iOS prior to 13.16.0.

12 Oct 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-12 10:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-5554

Mitre link : CVE-2023-5554

CVE.ORG link : CVE-2023-5554


JSON object : View

Products Affected

linecorp

  • line
CWE
CWE-295

Improper Certificate Validation