CVE-2023-44001: Medium severity line vulnerability
Published Jan 24, 2024
·Updated
An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Affected Software
1 affected component
linecorp Line=13.6.1
Event History
Jan 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-44001?
CVE-2023-44001 is classified as a high severity vulnerability due to the potential for attackers to exploit it by sending malicious notifications.
2
How do I fix CVE-2023-44001?
To remediate CVE-2023-44001, update the LINE application to the latest version beyond 13.6.1, where the vulnerability has been patched.
3
What type of vulnerability is CVE-2023-44001?
CVE-2023-44001 is a notification spoofing vulnerability caused by leakage of the channel access token.
4
Who is affected by CVE-2023-44001?
Users of the LINE app version 13.6.1 are affected by CVE-2023-44001.
5
What are the potential consequences of CVE-2023-44001?
If exploited, CVE-2023-44001 could allow attackers to send deceptive notifications, potentially leading to phishing or other malicious activities.