PT-2019-9955 · Amazon · Amazon Aws Sdk For Android
Publicado
2019-04-04
·
Atualizado
2021-05-10
·
CVE-2018-19981
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Amazon AWS SDK for Android versions <=2.8.5
Description
The issue allows an attacker to access plain text AWS STS Temporary Credentials stored by the Amazon AWS SDK for Android using Android SharedPreferences. These credentials can be used to create authenticated and/or authorized requests. However, exploitation requires the attacker to have "root" privilege access to the Android filesystem, implying the device has been compromised.
Recommendations
For Amazon AWS SDK for Android versions <=2.8.5, consider updating to a version greater than 2.8.5 to resolve the issue. As a temporary workaround, restrict access to the Android filesystem to minimize the risk of exploitation.
Exploit
Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Amazon Aws Sdk For Android