CVE-2019-17355

CRITICAL

Orbitz 19.31.1 - Sensitive Information Exposure in Log Files

Title source: llm
STIX 2.1

Description

In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://pastebin.com/GgpFz3ZW

Scores

CVSS v3 9.8
EPSS 0.0133
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-532
Status published
Products (1)
orbitz/orbitz 19.31.1
Published Oct 15, 2019
Tracked Since Feb 18, 2026