The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server certificates, which allows a man-in-the-middle attacker to spoof servers and obtain sensitive information via a crafted certificate.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-05T13:41:39.271Z
Reserved: 2024-02-26T01:49:51.712Z
Link: CVE-2024-27440
Updated: 2024-08-02T00:34:52.381Z
Status : Awaiting Analysis
Published: 2024-03-13T06:15:52.273
Modified: 2024-11-21T09:04:36.887
Link: CVE-2024-27440
No data.
OpenCVE Enrichment
No data.
Weaknesses