CVE-2023-22362

HIGH

SUSHIRO App for Android <4.0.31-<2.0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan SUSHIRO Ver.2.0.1

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (5)
akindo-sushiro/hong_kong_sushiro 3.0.3
akindo-sushiro/singapore_sushiro 2.0.3
akindo-sushiro/sushiro 4.0.31
akindo-sushiro/taiwan_sushiro 2.0.3
akindo-sushiro/thailand_sushiro 2.0.3
Published Feb 13, 2023
Tracked Since Feb 18, 2026