CVE-2019-19251 describes a vulnerability in the Last.fm desktop application (Last.fm Scrobbler) on macOS, versions through 2.1.39, where it transmits API keys over unencrypted HTTP by default, even though an SSL option exists. This medium-severity vulnerability (CVSS 5.3) allows for passive eavesdropping on network traffic to capture sensitive API keys due to the lack of encryption. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.39CPE matchmatch criteria | cpe:2.3:a:last.fm:last.fm_desktop:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.