{ "schema_version": "1.4.0", "id": "GHSA-c686-g9ff-6f7m", "modified": "2024-04-04T02:42:40Z", "published": "2022-05-24T17:03:09Z", "aliases": [ "CVE-2019-19251" ], "details": "The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19251" }, { "type": "WEB", "url": "https://getsatisfaction.com/lastfm/topics/why-doesnt-the-macos-client-enable-ssl-by-default-c1nh5k1s054ak" } ], "database_specific": { "cwe_ids": [ "CWE-1188" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-12-10T15:15:00Z" } }