Required CVE Record Information
Description
The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
References 3 Total
- jvndb.jvn.jp: JVNDB-2013-000054 third-party-advisory
- jvn.jp: JVN#39218538 third-party-advisory
- https://play.google.com/store/apps/details?id=jp.pizzahut.aorder
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- jvndb.jvn.jp: JVNDB-2013-000054 third-party-advisoryx_transferred
- jvn.jp: JVN#39218538 third-party-advisoryx_transferred
- https://play.google.com/store/apps/details?id=jp.pizzahut.aorder x_transferred