CVE-2017-13104: Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption
Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13104?
CVE-2017-13104 is classified as a high-severity vulnerability due to the use of a hard-coded encryption key.
How do I fix CVE-2017-13104?
To fix CVE-2017-13104, update the UberEATS app to a version that does not use hard-coded encryption keys.
What are the implications of CVE-2017-13104?
The implications of CVE-2017-13104 include potential unauthorized access to sensitive user data because the encryption key can be easily accessed.
Is CVE-2017-13104 actively being exploited?
There is no public information indicating that CVE-2017-13104 is actively being exploited at this time.
Who is affected by CVE-2017-13104?
Users of the UberEATS iOS application version 1.108.10001 are affected by CVE-2017-13104.