First published: Tue Jun 14 2022(Updated: )
'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16 improperly verifies server certificates, which may allow an attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Dena Mobaoku-auction \& Flea Market | <5.5.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-29482.
The title of this vulnerability is 'Mobaoku-Auction&Flea Market App for iOS versions prior to 5.5.16 improperly verifies server certificates'.
The severity of CVE-2022-29482 is medium with a severity value of 3.7.
The affected software for CVE-2022-29482 is 'Mobaoku-Auction&Flea Market' App for iOS versions prior to 5.5.16.
An attacker can exploit this vulnerability by performing a man-in-the-middle attack to eavesdrop on encrypted communication.