All incidents

PBL-06 Security audit results

Introduction

Vulnerabilities summary

IDProjectIssue nameSeverityStatus
PBL-06-001AndroidFingerprint bypass via activity invocationLowMitigated (1)
PBL-06-002iOSPossible leaks & Phishing via URL scheme hijackingMediumFixed in v1.3
PBL-06-005AndroidAccount information access via debug messagesMediumFixed in v1.1
PBL-06-006iOSMissing jailbreak detection on iOSMediumFixed in v1.3
PBL-06-007AndroidMissing root detection in AndroidMediumFixed in v1.3
PBL-06-008APIJWT key confusion leads to authentication bypassHighFixed in v3.3.1
PBL-06-009GO CLI (Community)Improper file permissions for configuration fileHighFixed in v0.1.4
PBL-06-008APIEmail HTML injection in JWT attack notificationsHighFixed v3.5

(1) Note PBL-06-001 WP1: Fingerprint bypass via activity invocation (LOW)

Miscellaneous issues

  • PBL-06-003: Android app hardening recommendations (Fixed v1.3)
  • PBL-06-004: Android binary hardening recommendations (In review)
  • PBL-06-011: Missing ACL checks on TransfersView controller (Fixed v3.5)
  • PBL-06-012: URL path traversal via command line flags (Open)
  • PBL-06-013: Improper escaping of resource fields (Fixed v0.1.5)
  • PBL-06-014: Server packages with known vulnerabilities (Process already in place)
  • PBL-06-015: Missing private key revocation process (In backlog)

Current status:

1. Acknowledge issue with reporter
2. Get a fix/patch prepared
3. Release new version
4. Prepare a report about the issue
5. Feature the problem in the release
Last updated: 2019-08-07 16:00:00 CET
Flag of European UnionMade in Europe. Privacy by default.
Passbolt Security Incident Report: audit - January 19th, 2022