CVE-2024-36279
MEDIUMDescription
Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.
Is your site exposed to CVE-2024-36279?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-36279? +
How severe is CVE-2024-36279? +
How do I check if I'm vulnerable to CVE-2024-36279? +
Related Vulnerabilities
Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high …
A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue affects the function send_email_change_user_email …