Credentials management in passport - CVE-2018-17500

 

Credentials management in passport - CVE-2018-17500

Published: March 21, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36057
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17500
CWE-ID: CWE-255
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.


Affected software

passport

How to mitigate CVE-2018-17500

Install update from vendor's website.


External References

Related Security Bulletins