Skip to content

Security

Thomas Oberndörfer edited this page Aug 27, 2019 · 8 revisions

Security Audits

Fixed vulnerabilities

  • Clickjacking (CVE-2019-9147). (fixed in Mailvelope v3.1.0)
  • Missing Message and Key Validity Checks (CVE-2019-9148). (fixed in Mailvelope v3.3.0)
  • Private Key Operations Require no User Interaction (CVE-2019-9149). (fixed in Mailvelope v3.3.0)
  • Key Import User Interaction Bypass (CVE-2019-9150). (fixed in Mailvelope v3.3.0)
  • XSS via HTML file download link. (fixed in Mailvelope v1.3.2) Detailed analysis
  • Bug in S2K allows decryption of malformed private key backup messages. (fixed in Mailvelope v1.2.0) Detailed analysis
  • Integrated documentation page can access privileged API. (fixed in Mailvelope v0.11.0) Detailed analysis
  • EME PKCS1 v1_5 padding bug in OpenPGP.js. (fixed in Mailvelope v0.8.0) Detailed analysis and blog post.