VYPR
Critical severity9.8NVD Advisory· Published Oct 15, 2019· Updated Jun 17, 2026

CVE-2019-17397

CVE-2019-17397

Description

In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

Affected products

3
  • DoorDash/DoorDash2 versions
    cpe:2.3:a:doordash:doordash:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:doordash:doordash:*:*:*:*:*:android:*:*range: <=11.5.2
    • (no CPE)range: <=11.5.2
  • DoorDash/DoorDash applicationdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.