Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-26833

Опубликовано: 06 апр. 2021
Источник: nvd
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:timelybills:timelybills:*:*:*:*:*:iphone_os:*:*
Версия до 1.7.0 (включая)
cpe:2.3:a:timelybills:timelybills:*:*:*:*:*:android:*:*
Версия до 1.21.115 (включая)

EPSS

Процентиль: 54%
0.00316
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 5.9
github
больше 3 лет назад

Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted.

EPSS

Процентиль: 54%
0.00316
Низкий

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-459