VYPR
Medium severity5.9NVD Advisory· Published Apr 6, 2021· Updated Jun 17, 2026

CVE-2021-26833

CVE-2021-26833

Description

Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted.

Affected products

4
  • cpe:2.3:a:timelybills:timelybills:*:*:*:*:*:android:*:*+ 2 more
    • cpe:2.3:a:timelybills:timelybills:*:*:*:*:*:android:*:*range: <=1.21.115
    • cpe:2.3:a:timelybills:timelybills:*:*:*:*:*:iphone_os:*:*range: <=1.7.0
    • (no CPE)range: <=1.7.0 for iOS, <=1.21.115 for Android
  • TimelyBills/TimelyBillsdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.