CVE-2024-8644CWE-315

Cleartext Storage of Sensitive Information in Oceanic Software's ValeApp

Critical · published September 27, 2024

CVSS v4.0
9.3
EPSS
0%
Percentile
18.7
In the wild
Unconfirmed
What it is

Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).

This issue affects ValeApp: before v2.0.0.

The record
Technical detail
CVSS v4.0
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
EPSS
0.00268 · 18.7th percentile
Weakness
CWE-315 · Cleartext Storage of Sensitive Information in a Cookie
Published
2024-09-27T11:48Z
EPSS history
Timeline
  • 27 SEP 11:48Z
    Cleartext Storage of Sensitive Information in Oceanic Software's ValeApp
    cvelistv5