PT-2019-18982 · Simple Bank · Simple

Publicado

2019-05-13

·

Atualizado

2020-08-24

·

CVE-2019-8350

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Simple - Better Banking application versions 2.45.0 through 2.45.3
Description The issue is related to an information disclosure problem where the user's password is leaked to the keyboard autocomplete functionality. This could allow third-party Android keyboards that capture the password to store it in cleartext or transmit it to third-party services for keyboard customization purposes. A compromise of any datastore containing keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.
Recommendations For versions 2.45.0 through 2.45.3, update to version 2.46.0 to resolve the issue. As a temporary workaround, consider disabling the keyboard autocomplete functionality for sensitive fields like passwords until the update is applied. Restrict access to third-party keyboards or use a keyboard that does not capture or store passwords to minimize the risk of exploitation.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8350

Produtos afetados

Simple