Use of hard-coded credentials in NewsPicks for Android - CVE-2023-28387
Published: June 30, 2023
Vulnerability identifier: #VU77829
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28387
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to presence of hard-coded credentials in application code. A remote attacker can analyze data in the app and obtain API key for an external service.
Affected software
NewsPicks for Android
NewsPicks for iOS
NewsPicks for iOS
How to mitigate CVE-2023-28387
Install updates from vendor's website.
NewsPicks for Android - update to 10.5.2
NewsPicks for iOS - update to 10.4.6
NewsPicks for iOS - update to 10.4.6