e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN15808274/ | Third Party Advisory |
https://shinsei.e-gov.go.jp/contents/news/2023-03-12t1022040900_1318.html | Release Notes |
https://jvn.jp/en/jp/JVN15808274/ | Third Party Advisory |
https://shinsei.e-gov.go.jp/contents/news/2023-03-12t1022040900_1318.html | Release Notes |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-11 01:15
Updated : 2024-11-21 08:25
NVD link : CVE-2023-44689
Mitre link : CVE-2023-44689
CVE.ORG link : CVE-2023-44689
JSON object : View
Products Affected
e-gov
- e-gov
CWE
CWE-862
Missing Authorization