Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse.This issue affects Tap&Sign App: before V.1.025.
The product uses an environment variable to store unencrypted sensitive information.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://docs.tapandsign.com/tap-and-sign/tap-and-sign-v.1.025-surum-notlari | release notes |
https://www.usom.gov.tr/bildirim/tr-25-0063 | third party advisory |