PT-2024-31799 · Microsoft+1 · Swiftkey+1

Lolcabanon

·

Published

2024-09-15

·

Updated

2024-09-23

·

CVE-2024-45833

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Mattermost Mobile Apps versions <=2.18.0
Description: The issue arises when the Mattermost Mobile Apps fail to disable autocomplete during login while typing the password and the visible password option is selected. This allows the password to be saved in the dictionary if the user has Swiftkey as the default keyboard and the password contains a special character. The masking of the password must be off for this issue to occur.
Recommendations: For Mattermost Mobile Apps versions <=2.18.0, update to a version higher than 2.18.0 to resolve the issue. As a temporary workaround, consider disabling the autocomplete feature in the Swiftkey keyboard settings or avoiding the use of special characters in passwords until a patch is available. Additionally, restricting access to the login feature or using a different keyboard can minimize the risk of exploitation.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2024-45833

Affected Products

Mattermost Mobile Apps
Swiftkey