PT-2018-9299 · Ionic Team · Cordova

R3Ggi

·

Publicado

2018-03-13

·

Atualizado

2018-04-16

·

CVE-2018-1000123

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Ionic Team Cordova plugin iOS Keychain versions before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf
Description: The issue is related to an Information Exposure Through Log Files, which can lead to the leakage of sensitive data such as login credentials and passwords. This can be exploited if an attacker has access to the victim's iOS logs.
Recommendations: For versions before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf, update to a version after commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf to resolve the issue. As a temporary workaround, consider restricting access to iOS logs to minimize the risk of exploitation.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000123

Produtos afetados

Cordova