VulnerabilityModified
CVE-2021-43512
An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.
MEDIUM 5.5EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cause unspecified consequences due to being able to decompile a local application and extract their API keys.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-922
- Affected
- flightradar24/flightradar24 flight tracker
- Source
- cve@mitre.org
References
- https://medium.com/%40janmejayaswainofficial/advisory-of-cve-2021-43512-5e54e6a93101
- https://www.flightradar24.comVendor Advisory
- https://www.flightradar24.com.aaBroken Link
- https://medium.com/%40janmejayaswainofficial/advisory-of-cve-2021-43512-5e54e6a93101
- https://www.flightradar24.comVendor Advisory
- https://www.flightradar24.com.aaBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.