All incidents

Sending unencrypted description during resource creation on Android app

Summary

  • CVE: N/A
  • Product affected: API (Pro and CE) and the Android app
  • Versions affected:
    • API version under v3.12.2
    • Android app under 1.13.2
  • Version fixed:
    • API v3.12.2
    • Android app 1.13.2
  • Affected component: Resources creation form.
  • Vulnerability Type: Information leak
  • Severity: Medium

Problem

Attack vector / exploitation

Who's impacted

Root cause

Android App

API

How to fix the issue

What was done to fix the issue

  • MOB-1250 Fix the Android app by not sending the description field to the backend during resource creation
  • PB-24315 Add validation of received resource fields on the backend according to the schema
  • PB-24315 Run a script to clear the description field in all resources of type encrypted password with encrypted description

Event Timeline

  • 20/04/2023 - Bug identified by Mobile team during UAT
  • 26/04/2023 - Android app fixed with 1.13.2
  • 26/04/2023 - API fixed with v3.12.2

Current status:

1. Acknowledge issue with reporter
2. Get a fix/patch prepared
3. Release new version
4. Prepare a report about the issue
5. Feature the problem in the release
Last updated: 2023-04-26 13:20:00 CET
Flag of European UnionMade in Europe. Privacy by default.
Passbolt Security Incident Report: vulnerability - April 26th, 2023