Cleartext storage of sensitive information in Twitter for Android - #VU23809

 

Cleartext storage of sensitive information in Twitter for Android - #VU23809

Published: December 26, 2019


Vulnerability identifier: #VU23809
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to insecure data storage issue. A local application on the device can gain unauthorized access to sensitive information of the Twitter application, such as Direct Messages, protected Tweets, location information.


Affected software

Twitter for Android

Remediation

Install updates from vendor's website.

Twitter for Android - update to 8.15.0-release.00

External References

Related Security Bulletins