PT-2019-18982 · Simple Bank · Simple

Published

2019-05-13

·

Updated

2020-08-24

·

CVE-2019-8350

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Simple - Better Banking application versions 2.45.0 through 2.45.3
Description The issue is related to an information disclosure problem where the user's password is leaked to the keyboard autocomplete functionality. This could allow third-party Android keyboards that capture the password to store it in cleartext or transmit it to third-party services for keyboard customization purposes. A compromise of any datastore containing keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.
Recommendations For versions 2.45.0 through 2.45.3, update to version 2.46.0 to resolve the issue. As a temporary workaround, consider disabling the keyboard autocomplete functionality for sensitive fields like passwords until the update is applied. Restrict access to third-party keyboards or use a keyboard that does not capture or store passwords to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-8350

Affected Products

Simple