Skip to content

Seed phrase stored in plaintext on Concordium Wallet for Android

Critical
concordium-cl published GHSA-5q4g-qc27-964f Mar 24, 2023

Package

No package listed

Affected versions

< 1.1.5

Patched versions

1.1.5

Description

Issue

The seed phrase (in byte format, as a seed) is stored in plain on the file system of the device among the shared preferences.

Patches

The seed phrase will be stored encrypted in the new release. The unencrypted version will be deleted.

The bug and fix is described in PR #192.

It is applied automatically once the user logs in to the updated version (1.1.5).

Acknowledgement

Thank you to Frontier, who reported the issue.

Timeline

  • Report date: 24-01-2023
  • Acknowledgement of issue: 03-02-2023
  • Fix date: 22-02-2023
  • Release date: 27-02-2023

Workarounds

None.

References

Release announcement

Severity

Critical

CVE ID

No known CVE

Weaknesses

No CWEs