Description
The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-02T22:16:46.259Z
Reserved: 2023-12-07T02:39:43.973Z
Link: CVE-2023-50294
No data.
Status : Modified
Published: 2023-12-26T08:15:11.427
Modified: 2024-11-21T08:36:48.760
Link: CVE-2023-50294
No data.
OpenCVE Enrichment
No data.
Weaknesses