CVE-2019-17355

CRITICAL

Orbitz - Log Information Exposure

Title source: rule
STIX 2.1

Description

In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/GgpFz3ZW

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-532
Status published
Products (1)
orbitz/orbitz 19.31.1
Published Oct 15, 2019
Tracked Since Feb 18, 2026