CVE-2023-39737: Infoleak
Published Oct 24, 2023
·Updated
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Affected Software
1 affected component
linecorp Matsuya=13.6.1
Event History
Oct 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-39737?
The severity of CVE-2023-39737 is high (8.2).
2
What is the impact of CVE-2023-39737?
CVE-2023-39737 allows attackers to obtain the channel access token and send crafted broadcast messages.
3
How does CVE-2023-39737 occur?
CVE-2023-39737 occurs due to the leakage of the client secret in Matsuya Line 13.6.1.
4
Which software version is affected by CVE-2023-39737?
The software version affected by CVE-2023-39737 is Matsuya Line 13.6.1.
5
How can I fix CVE-2023-39737?
To fix CVE-2023-39737, update to a secure version of Matsuya Line and ensure the client secret is properly protected.