First published: Wed Jan 24 2024(Updated: )
An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LINE | =13.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43995 is rated as a medium severity vulnerability due to the potential for attackers to exploit the leakage of the channel access token.
To fix CVE-2023-43995, update the Line app to a version beyond v13.6.1 that addresses the notification handling issues.
CVE-2023-43995 specifically affects the Line app version 13.6.1.
CVE-2023-43995 allows attackers to send crafted malicious notifications by exploiting a leaked channel access token.
Yes, CVE-2023-43995 can lead to data breaches if attackers successfully exploit the vulnerability to access sensitive information.