CVE-2018-17499 describes a sensitive information disclosure vulnerability in Envoy Passport for Android and iPhone, where unencrypted API keys, tokens, and other sensitive data are stored in application logs. This medium-severity flaw (CVSS 5.5) allows a local attacker with low privileges and no user interaction to access this information, leading to a high confidentiality impact. There is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. While community discussion and media coverage are limited, the vulnerability was highlighted in a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.5CPE matchmatch criteria | cpe:2.3:a:envoy:passport:2.2.5:*:*:*:*:iphone_os:*:* | ||
2.4.0CPE matchmatch criteria | cpe:2.3:a:envoy:passport:2.4.0:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.