vendor:
Werewolf Online
by:
ManhNho
7.5
CVSS
HIGH
Insecure Logging
532
CWE
Product Name: Werewolf Online
Affected Version From: 2000.8.8
Affected Version To: 2000.8.8
Patch Exists: YES
Related CWE: CVE-2018-11505
CPE: a:werewolfapps:werewolf_online:0.8.8
Platforms Tested: Android
2018
Werewolf Online 0.8.8 – Insecure Logging
Many developers log information to the android log. Sometimes sensitive data as well. With output of logcat, Hacker can get "Firebase token" which used in PUT request to /players/meAndCheckAppVersion
Mitigation:
Developers should avoid logging sensitive information and use proper logging mechanisms that do not expose sensitive data