Urban Airship operates a cloud-based mobile engagement platform, with its vulnerability footprint concentrated in OAuth 2.0 authentication components used across its SDKs and integrations. Observed issues reflect access-control and authentication implementation challenges in credential-handling and token-validation logic. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Urbanairship over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4347MEDIUM The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote | May 20, 2014 | 5.8 | 17 | NO | NO |
CVE-2013-4346MEDIUM The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL. | May 20, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Urbanairship.
Media articles that mention a CVE ID that affects a product developed by Urbanairship — matched by CVE ID, not by vendor name.