Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-08T12:44:11
Updated: 2024-08-04T23:10:30.839Z
Reserved: 2019-05-17T00:00:00
Link: CVE-2019-12171
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-07-08T13:15:10.667
Modified: 2024-11-21T04:22:21.727
Link: CVE-2019-12171
Redhat
No data.