Unrated severityNVD Advisory· Published Jan 28, 2014· Updated Apr 29, 2026
CVE-2014-0647
CVE-2014-0647
Description
The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- seclists.org/fulldisclosure/2014/Jan/123nvd
- seclists.org/fulldisclosure/2014/Jan/64nvd
- www.osvdb.org/102514nvd
- www.securityfocus.com/archive/1/530756/100/0/threadednvd
- www.securityfocus.com/bid/64942nvd
- www.zdnet.com/starbucks-fixes-ios-app-bugs-7000025323/nvd
- www.zdnet.com/the-starbucks-bug-not-as-awful-as-reported-7000025269/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/90412nvd
- itunes.apple.com/us/app/starbucks/id331177714nvd
News mentions
0No linked articles in our index yet.