Cleartext storage of sensitive information in parse-server - CVE-2020-26288

 

Cleartext storage of sensitive information in parse-server - CVE-2020-26288

Published: December 30, 2020


Vulnerability identifier: #VU49206
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-26288
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: MeetFox
Affected software:
parse-server

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to application stores passwords involved in LDAP authentication in cleartext. An attacker with ability to access the application can obtain passwords in clear text.


How to mitigate CVE-2020-26288

Install updates from vendor's website.

Sources