CVE-2018-19981 describes a vulnerability in Amazon AWS SDK for Android versions <=2.8.5, where AWS STS Temporary Credentials obtained via AWS Cognito Identity Service are stored in plain text within Android SharedPreferences. This allows an attacker with root access to a compromised Android device to retrieve these credentials and use them to make authenticated and authorized requests. The vulnerability is rated as HIGH severity (CVSS 7.2) due to the potential for complete compromise of confidentiality, integrity, and availability, though it requires high privileges (root access) on the target device. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.5CPE matchmatch criteria | cpe:2.3:a:amazon:aws_software_development_kit:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.