
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in A-WORLD OIRASE BEER_waiting Line v.13.6.1 that allows attackers to send crafted notifications by exploiting a leaked channel access token. The vulnerability was identified and assigned CVE-2023-45561. This security issue involves the exposure of sensitive credentials that could be used to compromise the Line messaging platform's communication channel (GitHub Report).
The vulnerability stems from the exposure of a client secret in the response from the endpoint 'https://asia-northeast1-pibot-order-prod.cloudfunctions.net/userEntry'. This leaked client secret can be used to obtain a channel access token, which is a critical credential for securing communication channels within Line. The exploit can be triggered simply by having Line installed and opening the mini-app 'OIRASE BEER_waiting' (GitHub Report).
The vulnerability affects all users of the OIRASE BEER_waiting mini-app. When exploited, attackers can use the obtained channel access token to broadcast malicious messages through the Line platform, including potentially fraudulent information and malicious website links (GitHub Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."