« Volver al listado

CVE-2019-16681

Estado: ModificadaMedia (4.7)—

The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has not agreed that this issue has serious impact. The vendor states that the issue is not critical because it does not allow Elevation of Privilege, Sensitive Data Leakage, or any critical unauthorized activity from a malicious user. The vendor also states that a victim must first install a malicious APK to their application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-16681",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-09-21T21:15:10.733",
  "references": [
    {
      "url": "https://github.com/tarantula-team/Traveloka-Android-App-Critical-Vulnerability",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://web.archive.org/web/20190923165849/https://github.com/tarantula-team/Traveloka-Android-App-Critical-Vulnerability",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://github.com/tarantula-team/Traveloka-Android-App-Critical-Vulnerability",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI. (When in physical possession of the device, opening local files is also possible.) NOTE: As of 2019-09-23, the vendor has not agreed that this issue has serious impact. The vendor states that the issue is not critical because it does not allow Elevation of Privilege, Sensitive Data Leakage, or any critical unauthorized activity from a malicious user. The vendor also states that a victim must first install a malicious APK to their application."
    },
    {
      "lang": "es",
      "value": "La aplicación Traveloka versión 3.14.0 para Android exporta com.traveloka.android.activity.common.WebViewActivity, lo que conlleva a la apertura de URL arbitrarias, que pueden inyectar contenido engañoso en la interfaz de usuario. (Cuando esté en posesión física del dispositivo, también es posible abrir archivos locales). NOTA: A partir del 23/09/2019, el proveedor no ha acordado que este problema tenga un impacto grave. El proveedor declara que el problema no es crítico porque no permite la Elevación de privilegios, la Fugas de datos confidenciales o cualquier actividad crítica no autorizada de un usuario malintencionado. El proveedor también afirma que una víctima primero debe instalar un APK malicioso en su aplicación."
    }
  ],
  "lastModified": "2026-06-17T02:22:34.373",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:traveloka:traveloka:3.14.0:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DE515D2-5010-40C8-AF57-7E4D76FBB268"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}