← Back to CVE List

CVE-2021-40527

Published: 2021-10-25T11:15Z
Last Modified: 2024-11-21T06:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt