VulnerabilityModified
CVE-2023-39731
The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
MEDIUM 5.3EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- line/kaibutsunosato
- Source
- cve@mitre.org
References
- https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39731.mdThird Party Advisory
- https://liff.line.me/1657662489-pwEQNzJ4Vendor Advisory
- https://github.com/syz913/CVE-reports/blob/main/CVE-2023-39731.mdThird Party Advisory
- https://liff.line.me/1657662489-pwEQNzJ4Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.