daaswebclient
v1.2.0
Published
DaaS web client common utilities
Readme
daaswebclient
This package was registered as part of authorized security research for the T-Mobile Bug Bounty Program via Bugcrowd.
It demonstrates a dependency confusion vulnerability where the internal package name daaswebclient was found in the DIGITS desktop application (com.tmobile.phone2) via a hardcoded file:// path:
"digits-common": "file://Users/RHeimbe2/GitLab/daaswebclient/packages/digits-common"This is not malicious software. The preinstall script sends minimal diagnostic info (hostname, username, IP) to prove exploitability.
