Security Advisory

CVE-2021-40527

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-10-25 10:40:53
Last updated 2024-08-04 02:44:10
Assigner mitre
CVSS score 8.6
State PUBLISHED

Description

Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application.