CVE-2019-19251
10.12.2019, 15:15
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.Enginsight
Vendor | Product | Version |
---|---|---|
last.fm | last.fm_desktop | 𝑥 ≤ 2.1.39 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration