Vulnerabilities > Envoy

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2018-17500 Insufficiently Protected Credentials vulnerability in Envoy Passport 2.2.5/2.4.0
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext.
local
low complexity
envoy CWE-522
7.8
2019-03-21 CVE-2018-17499 Cleartext Storage of Sensitive Information vulnerability in Envoy Passport 2.2.5/2.4.0
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs.
local
low complexity
envoy CWE-312
5.5