PT-2018-9299 · Ionic Team · Cordova
R3Ggi
·
Publicado
2018-03-13
·
Atualizado
2018-04-16
·
CVE-2018-1000123
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Ionic Team Cordova plugin iOS Keychain versions before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf
Description:
The issue is related to an Information Exposure Through Log Files, which can lead to the leakage of sensitive data such as login credentials and passwords. This can be exploited if an attacker has access to the victim's iOS logs.
Recommendations:
For versions before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf, update to a version after commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf to resolve the issue. As a temporary workaround, consider restricting access to iOS logs to minimize the risk of exploitation.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cordova