SB2025040368 - Weak cryptographic algorithm in Musicshelf
Published: April 3, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of a broken or risky cryptographic algorithm (CVE-ID: CVE-2024-2365)
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to software uses a weak SHA-1 Message_Digest algorithm within the IsValidPin() function in io\fabric\sdk\android\services\network\PinningTrustManager.java. An attacker with physical access to the system can bypass SSL pinning protection and intercept traffic sent by the application.
Remediation
Install update from vendor's website.