OSV 1.4.0 · unreviewed · 修改于 2022-05-04 08:00
发布时间
2021-11-25 08:00
GitHub 审查时间
—
NVD 发布时间
2021-11-25 00:15
源文件
advisories/unreviewed/2021/11/GHSA-2hf9-98xv-3h7h/GHSA-2hf9-98xv-3h7h.json
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari account's access token being obtained.
该公告没有提供结构化的受影响软件包信息。