Envoy's vulnerability profile centers on its Passport product and reflects a narrow, focused footprint characterized by credential and secrets-handling issues such as cleartext storage of sensitive information, insertion of secrets into log files, and insufficiently protected credentials. These patterns suggest an authentication or identity-management component where data exposure through logging or storage represents the primary concern; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Envoy over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17500HIGH Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. | Mar 21, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-17499MEDIUM Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacke | Mar 21, 2019 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Envoy.
Media articles that mention a CVE ID that affects a product developed by Envoy — matched by CVE ID, not by vendor name.