Cleartext storage of sensitive information in Twitter for Android - #VU23809
Published: December 26, 2019
Vulnerability identifier: #VU23809
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to insecure data storage issue. A local application on the device can gain unauthorized access to sensitive information of the Twitter application, such as Direct Messages, protected Tweets, location information.
Affected software
Twitter for Android
Remediation
Install updates from vendor's website.
Twitter for Android - update to 8.15.0-release.00