An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-04-26T00:00:00

Updated: 2024-08-02T02:36:04.567Z

Reserved: 2024-04-26T00:00:00

Link: CVE-2024-33669

cve-icon Vulnrichment

Updated: 2024-04-29T12:12:35.925Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-26T01:15:46.383

Modified: 2024-07-03T01:58:35.420

Link: CVE-2024-33669

cve-icon Redhat

No data.