Headline
CVE-2023-39507: "Rikunabi NEXT" App for Android fails to restrict custom URL schemes properly
Improper authorization in the custom URL scheme handler in “Rikunabi NEXT” App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.
Published:2023/08/09 Last Updated:2023/08/09
Overview
“Rikunabi NEXT” App for Android provided by Recruit Co., Ltd. fails to restrict custom URL schemes properly.
Products Affected
- “Rikunabi NEXT” App for Android prior to ver. 11.5.0
Description
“Rikunabi NEXT” App for Android provided by Recruit Co., Ltd. provides the function to access a requested URL using Custom URL Scheme. The App does not restrict access to the function properly (CWE-939) which may be exploited to direct the App to access any sites.
Impact
A remote attacker may lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Solution
Update the Application
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version that fixes the vulnerability.
- “Rikunabi NEXT” App for Android ver. 11.5.0
Vendor Status
Vendor
Status
Last Update
Vendor Notes
Recruit Co., Ltd.
Vulnerable
2023/08/09
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector(AV)
Physical §
Local (L)
Adjacent (A)
Network (N)
Attack Complexity(AC)
High (H)
Low (L)
Privileges Required(PR)
High (H)
Low (L)
None (N)
User Interaction(UI)
Required ®
None (N)
Scope(S)
Unchanged (U)
Changed ©
Confidentiality Impact©
None (N)
Low (L)
High (H)
Integrity Impact(I)
None (N)
Low (L)
High (H)
Availability Impact(A)
None (N)
Low (L)
High (H)
CVSS v2 AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector(AV)
Local (L)
Adjacent Network (A)
Network (N)
Access Complexity(AC)
High (H)
Medium (M)
Low (L)
Authentication(Au)
Multiple (M)
Single (S)
None (N)
Confidentiality Impact©
None (N)
Partial §
Complete ©
Integrity Impact(I)
None (N)
Partial §
Complete ©
Availability Impact(A)
None (N)
Partial §
Complete ©
Credit
Nao Komatsu of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information