HomeDefault status
unaffected
Any version before 1.1.15
affected
Description
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
Problem types
CWE-522 Insufficiently Protected Credentials
Product status
Any version before 1.1.15
Credits
Jerry Gamblin (https://github.com/jgamblin)
References
github.com/CERTCC/cveClient/pull/39 (Github PR to fix the issue)
github.com/CERTCC/cveClient/ (Github Repository of the project.)