{ "schema_version": "1.4.0", "id": "GHSA-f2mx-7p4c-2cvr", "modified": "2025-04-11T04:18:33Z", "published": "2022-05-14T02:53:59Z", "aliases": [ "CVE-2014-0647" ], "details": "The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0647" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90412" }, { "type": "WEB", "url": "https://itunes.apple.com/us/app/starbucks/id331177714?mt=8" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2014/Jan/123" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2014/Jan/64" }, { "type": "WEB", "url": "http://www.osvdb.org/102514" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/530756/100/0/threaded" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/64942" }, { "type": "WEB", "url": "http://www.zdnet.com/starbucks-fixes-ios-app-bugs-7000025323" }, { "type": "WEB", "url": "http://www.zdnet.com/the-starbucks-bug-not-as-awful-as-reported-7000025269" } ], "database_specific": { "cwe_ids": [], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-01-28T00:55:00Z" } }