Vulnerabilities > Envoy

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2018-17500 Insufficiently Protected Credentials vulnerability in Envoy Passport 2.2.5/2.4.0
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext.
local
low complexity
envoy CWE-522
2.1
2019-03-21 CVE-2018-17499 Information Exposure Through Log Files vulnerability in Envoy Passport 2.2.5/2.4.0
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs.
local
low complexity
envoy CWE-532
2.1