CVE-2024-36277

MEDIUM

FreeFrom <1.3.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-347
Status published
Products (2)
FreeFrom K.K./"FreeFrom - the nostr client" App for Android prior to 1.3.5
FreeFrom K.K./"FreeFrom - the nostr client" App for iOS prior to 1.3.5
Published Jun 17, 2024
Tracked Since Feb 18, 2026