PoC Index

CVE-2020-12624

MEDIUM 6.5EPSS 1.3%

The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.30% chance of exploitation in the next 30 days, 68th percentile
Published
2020-05-03
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related