Cleartext storage of sensitive information in parse-server - CVE-2020-26288

 

Cleartext storage of sensitive information in parse-server - CVE-2020-26288

Published: December 30, 2020


Vulnerability identifier: #VU49206
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26288
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to application stores passwords involved in LDAP authentication in cleartext. An attacker with ability to access the application can obtain passwords in clear text.


Affected software

parse-server

How to mitigate CVE-2020-26288

Install updates from vendor's website.

parse-server - update to 4.5.0

External References

Related Security Bulletins