Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27956
HistoryNov 20, 2020 - 10:16 a.m.

Information Disclosure

2020-11-2010:16:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
33
firefox
vulnerability
information disclosure
software keyboards
password field
local user
stored passwords

EPSS

0.001

Percentile

48.0%

firefox is vulnerable to information disclosure. The vulnerability exists due to the way software keyboards are handled by the Firefox. Some websites have a feature “Show Password” where clicking a button will change a password field into a textbook field, revealing the typed password.If and when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility for the software keyboard to remember the typed password.A local user leverage this behavior to gain access to passwords, stored by software keyboards.