W aplikacji com.dropbox.android 98.2.2 dla Androida ujawniona została podatność w funkcji Passcode umożliwiająca bypass autentykacji poprzez manipulację w czasie wykonania zmuszającą określoną metodę do zwrócenia wartości true. Atakujący mógłby zatem uwierzytelnić się przy użyciu dowolnego kodu PIN. UWAGA: producent wskazuje, że nie traktuje to jako zagrożenie w ramach swojego modelu threat model, który wyklucza urządzenia Android z uprzywilejowanym dostępem (rootem).
▸ Pokaż oryginał (EN)
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NDropbox
APPDropbox98.2.2
Powiązane podatności
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store...
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (To...
dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local use...
Odkryto problem w aplikacji com.dropbox.android wersja 98.2.2 dla Androida. Klasa FingerprintManager służąca d...
Samly (Elixir): wygasłe sesje SAML nie są unieważniane — błąd kontroli dostępu