Credentials management in passport - CVE-2018-17500
Published: March 21, 2019 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.