VYPR
Low severity2.9NVD Advisory· Published Mar 21, 2019· Updated Jun 17, 2026

CVE-2018-17500

CVE-2018-17500

Description

Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.

Affected products

5
  • Envoy/Passport2 versions
    cpe:2.3:a:envoy:passport:2.2.5:*:*:*:*:iphone_os:*:*+ 1 more
    • cpe:2.3:a:envoy:passport:2.2.5:*:*:*:*:iphone_os:*:*
    • cpe:2.3:a:envoy:passport:2.4.0:*:*:*:*:android:*:*
  • (expand)+ 2 more
    • (no CPE)
    • (no CPE)range: 2.4.0
    • (no CPE)range: 2.2.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.