First published: Tue Oct 24 2023(Updated: )
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linecorp Matsuya | =13.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-39737 is high (8.2).
CVE-2023-39737 allows attackers to obtain the channel access token and send crafted broadcast messages.
CVE-2023-39737 occurs due to the leakage of the client secret in Matsuya Line 13.6.1.
The software version affected by CVE-2023-39737 is Matsuya Line 13.6.1.
To fix CVE-2023-39737, update to a secure version of Matsuya Line and ensure the client secret is properly protected.