CVE-2014-1423: Signond Project Signond
Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.
Affected products
- Signond Project Signond: before 8.57\+15.04.20141127.1-0ubuntu1 (fixed in 8.57\+15.04.20141127.1-0ubuntu1)
- Ubports Ubuntu Touch: affected versions not specified
Published 2020-05-07. Last modified 2026-06-17.