Vulnerability CVE-2024-32988


Published: 2024-05-22

Description:
'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.

 References:
https://jvn.jp/en/jp/JVN83405304/

Copyright 2026, cxsecurity.com

 

Back to Top