PT-2019-18982 · Simple Bank · Simple
Published
2019-05-13
·
Updated
2020-08-24
·
CVE-2019-8350
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Simple - Better Banking application versions 2.45.0 through 2.45.3
Description
The issue is related to an information disclosure problem where the user's password is leaked to the keyboard autocomplete functionality. This could allow third-party Android keyboards that capture the password to store it in cleartext or transmit it to third-party services for keyboard customization purposes. A compromise of any datastore containing keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.
Recommendations
For versions 2.45.0 through 2.45.3, update to version 2.46.0 to resolve the issue. As a temporary workaround, consider disabling the keyboard autocomplete functionality for sensitive fields like passwords until the update is applied. Restrict access to third-party keyboards or use a keyboard that does not capture or store passwords to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple