SB2020123003 - Cleartext storage of passwords in parse-server NPM package
Published: December 30, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext storage of sensitive information (CVE-ID: CVE-2020-26288)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores passwords involved in LDAP authentication in cleartext. An attacker with ability to access the application can obtain passwords in clear text.
Remediation
Install update from vendor's website.