Cleartext storage of sensitive information in passport - CVE-2018-17499
Published: March 21, 2019 / Updated: August 8, 2020
passport
Detailed vulnerability description
The vulnerability allows a local authenticated user to gain access to sensitive information.
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.