CVE Vulnerabilities

CVE-2023-4984

Plaintext Storage of a Password

Published: Sep 15, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was found in didi KnowSearch 0.3.2/0.3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file /api/es/admin/v3/security/user/1. The manipulation leads to unprotected storage of credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239795.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

Name Vendor Start Version End Version
Knowsearch Didiglobal 0.3.1.2 (including) 0.3.1.2 (including)
Knowsearch Didiglobal 0.3.2 (including) 0.3.2 (including)

Potential Mitigations

References