CVE-2024-32988
EUVD-2024-3073322.05.2024, 08:15
'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| iplug | offerbox_app_for_android | 2.0.0 ≤ 𝑥 ≤ 2.3.17 | ADP |
| iplug | offerbox_app_for_ios | 2.17 ≤ 𝑥 ≤ 2.6.14 | ADP |