Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hv5g-q4h3-64q4 | Hard-coded credentials in org.folio:mod-remote-storage |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-05-30T14:24:51.975Z
Reserved: 2024-01-19T17:35:09.985Z
Link: CVE-2024-23685
Updated: 2024-08-01T23:06:25.360Z
Status : Modified
Published: 2024-01-19T21:15:10.470
Modified: 2025-05-30T15:15:36.670
Link: CVE-2024-23685
No data.
OpenCVE Enrichment
No data.
Github GHSA