CVE-2014-0647

low
Published 2014-01-28 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
macos macosnot-affected

Application impact

VendorProductVersionsFixed
starbucksstarbucks2.6.1

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.