CVE-2018-17500

LOW

Envoy Passport - Info Disclosure

Title source: llm

Description

Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.

Scores

CVSS v3 2.9
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (2)

envoy/passport
envoy/passport

Timeline

Published Mar 21, 2019
Tracked Since Feb 18, 2026