CVE-2018-19981

CVE-2018-19981

A cleartext-credential issue was discovered in the Amazon AWS SDK 2.8.5 for Android. This SDK uses Android SharedPreferences to store AWS STS Temporary Credentials retrieved by AWS Cognito Identity Provider. If a Mobile Application (MA) uses AWS Cognito in the authentication or authorization process, the AWS SDK will store these credentials in cleartext inside the "com.amazonaws.android.auth" SharedPref. An attacker can use these credentials to create and sign valid AWS Signature v4 requests, and perform authenticated and authorized application actions at the user’s expense. Note that the attacker must have root access to the Android filesystem (i.e., the device must already be compromised, such as by malware).

Source: CVE-2018-19981

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다