PT-2019-9955 · Amazon · Amazon Aws Sdk For Android
Published
2019-04-04
·
Updated
2021-05-10
·
CVE-2018-19981
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Amazon AWS SDK for Android versions <=2.8.5
Description
The issue allows an attacker to access plain text AWS STS Temporary Credentials stored by the Amazon AWS SDK for Android using Android SharedPreferences. These credentials can be used to create authenticated and/or authorized requests. However, exploitation requires the attacker to have "root" privilege access to the Android filesystem, implying the device has been compromised.
Recommendations
For Amazon AWS SDK for Android versions <=2.8.5, consider updating to a version greater than 2.8.5 to resolve the issue. As a temporary workaround, restrict access to the Android filesystem to minimize the risk of exploitation.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Aws Sdk For Android