PT-2022-19889 · Agilebits · 1Password

Published

2022-05-09

·

Updated

2022-05-18

·

CVE-2022-29868

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 1Password for Mac versions 7.2.4 through 7.9.x before 7.9.3
Description The issue allows malicious software running on the same computer to bypass process validation and exfiltrate secrets from 1Password, including vault items and derived values used for signing in, provided that 1Password is running and unlocked.
Recommendations For versions 7.2.4 through 7.9.x before 7.9.3, update to version 7.9.3 or later to resolve the issue.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29868

Affected Products

1Password