The SNKRDUNK Market Place App for iOS versions prior to 2.2.0 does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on and/or alter encrypted communication via a crafted certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://snkrdunk.com/information/37/ | mitigation vendor advisory |
https://jvn.jp/en/jp/JVN10168753/index.html | third party advisory |