Sensitive Token Information Exposed in Dark Horse Comics Android App Logs

Sensitive Token Information Exposed in Dark Horse Comics Android App Logs

CVE-2019-17398 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.

Learn more about our Cis Benchmark Audit For Google Android.