CVE Vulnerabilities

CVE-2023-4984

Plaintext Storage of a Password

Published: Sep 15, 2023 | Modified: May 17, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file /api/es/admin/v3/security/user/1. The manipulation leads to unprotected storage of credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239795.

Weakness

Storing a password in plaintext may result in a system compromise.

Affected Software

Name Vendor Start Version End Version
Knowsearch Didiglobal 0.3.1.2 (including) 0.3.1.2 (including)
Knowsearch Didiglobal 0.3.2 (including) 0.3.2 (including)

Potential Mitigations

References