A vulnerability classified as problematic was found in...
Low severity
Unreviewed
Published
Mar 11, 2024
to the GitHub Advisory Database
•
Updated Mar 11, 2024
Description
Published by the National Vulnerability Database
Mar 11, 2024
Published to the GitHub Advisory Database
Mar 11, 2024
Last updated
Mar 11, 2024
A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the component SHA-1 Handler. The manipulation leads to password hash with insufficient computational effort. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-256321 was assigned to this vulnerability.
References