PT-2018-11178 · Dropbox · Com.Dropbox.Android
Boonpoj Thongakaraniroj
+1
·
Publicado
2018-06-20
·
Atualizado
2024-08-05
·
CVE-2018-12445
CVSS v2.0
3.3
Baixa
| Vetor | AV:L/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
com.dropbox.android version 98.2.2
Description
An issue in the com.dropbox.android application allows authentication bypass through the FingerprintManager class for Biometric validation. This is possible because the fingerprint API, in conjunction with the Android keyGenerator class, is not properly implemented, enabling an attacker to authenticate with an arbitrary fingerprint. The vendor notes that this issue is not considered a threat within their threat model, specifically excluding Android devices that have been rooted.
Recommendations
For version 98.2.2, consider disabling the FingerprintManager class for Biometric validation until a proper fix is implemented to prevent authentication bypass. Restrict access to the fingerprint API to minimize the risk of exploitation. Avoid using the fingerprint authentication method in the affected application until the issue is resolved.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Com.Dropbox.Android