Cleartext storage of sensitive information in parse-server - CVE-2020-26288
Published: December 30, 2020
Vulnerability identifier: #VU49206
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-26288
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: MeetFox
Affected software:
parse-server
parse-server
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to application stores passwords involved in LDAP authentication in cleartext. An attacker with ability to access the application can obtain passwords in clear text.
How to mitigate CVE-2020-26288
Install updates from vendor's website.