CVE-2019-17397: Doordash
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
Affected products
- Doordash Doordash: up to and including 11.5.2
Published 2019-10-15. Last modified 2026-06-17.