CVE-2024-23453
MEDIUMspooncast/spoon 7.11.1-8.6.0 - Hard-coded Credentials Exposure
Title source: llmDescription
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.
References (3)
Core 3
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN96154238/
Vendor Advisory
https://spoon-support.spooncast.net/jp/update
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
5.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-798
Status
published
Products (1)
spooncast/spoon
7.11.1 - 8.6.0
Published
Jan 24, 2024
Tracked Since
Feb 18, 2026