CVE-2014-0647: Low severity Starbucks Starbucks vulnerability
The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of the Starbucks 2.6.1 application for iOS are exposed if sensitive data has been written to the Crashlytics session.clslog file and another application can read that file.
What access does an attacker need to obtain the leaked information?
The attacker needs local access sufficient to use an application that can read /Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog. The vulnerability does not require authentication according to the provided vector.
What information could be recovered from the log?
The log may contain usernames, passwords, and email addresses in plaintext.
How can I check whether a device is affected?
Check whether the Starbucks iOS application is version 2.6.1 and inspect the Crashlytics log at /Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog for plaintext sensitive information.