Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
References
| Link | Resource |
|---|---|
| https://huntr.dev/bounties/db6c32f4-742e-4262-8fd5-cefd0f133416 | Third Party Advisory |
| https://github.com/pimcore/customer-data-framework/commit/d1d58c10313f080737dc1e71fab3beb12488a1e6 | Patch |
Configurations
History
31 May 2023, 19:21
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
| First Time |
Pimcore customer-data-framework
Pimcore |
|
| CPE | cpe:2.3:a:pimcore:customer-data-framework:*:*:*:*:*:*:*:* | |
| References | (CONFIRM) https://huntr.dev/bounties/db6c32f4-742e-4262-8fd5-cefd0f133416 - Third Party Advisory | |
| References | (MISC) https://github.com/pimcore/customer-data-framework/commit/d1d58c10313f080737dc1e71fab3beb12488a1e6 - Patch | |
| CWE | CWE-522 |
25 May 2023, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-05-25 09:15
Updated : 2023-05-31 19:21
NVD link : CVE-2023-2881
Mitre link : CVE-2023-2881
JSON object : View
Products Affected
pimcore
- customer-data-framework
CWE
CWE-522
Insufficiently Protected Credentials
