PT-2024-31799 · Microsoft+1 · Swiftkey+1
Lolcabanon
·
Published
2024-09-15
·
Updated
2024-09-23
·
CVE-2024-45833
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Mattermost Mobile Apps versions <=2.18.0
Description:
The issue arises when the Mattermost Mobile Apps fail to disable autocomplete during login while typing the password and the visible password option is selected. This allows the password to be saved in the dictionary if the user has Swiftkey as the default keyboard and the password contains a special character. The masking of the password must be off for this issue to occur.
Recommendations:
For Mattermost Mobile Apps versions <=2.18.0, update to a version higher than 2.18.0 to resolve the issue. As a temporary workaround, consider disabling the autocomplete feature in the Swiftkey keyboard settings or avoiding the use of special characters in passwords until a patch is available. Additionally, restricting access to the login feature or using a different keyboard can minimize the risk of exploitation.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost Mobile Apps
Swiftkey