CVE-2019-17355: Orbitz

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.

Affected products

  • Orbitz Orbitz: version 19.31.1 only

Published 2019-10-15. Last modified 2026-06-17.