CVE-2018-17499: Medium severity envoy passport vulnerability
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17499?
CVE-2018-17499 is considered to have a high severity due to the potential exposure of sensitive information.
How do I fix CVE-2018-17499?
To fix CVE-2018-17499, ensure that logs do not store unencrypted sensitive information and update to the latest versions of Envoy Passport.
What versions are affected by CVE-2018-17499?
CVE-2018-17499 affects Envoy Passport for iPhone version 2.2.5 and Envoy Passport for Android version 2.4.0.
What type of information is exposed in CVE-2018-17499?
CVE-2018-17499 can expose sensitive information such as two API keys and a token.
Who can exploit CVE-2018-17499?
CVE-2018-17499 can be exploited by local attackers who have access to the logs containing unencrypted data.