Cleartext storage of sensitive information in SPIP - #VU50783
Published: February 17, 2021
Vulnerability identifier: #VU50783
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to secrets ares stored in a session file. A local user with access to the session files on the server can obtain credentials of website users.
Affected software
SPIP
spip (Debian package)
spip (Debian package)
Remediation
Install updates from vendor's website.
SPIP - addressed in versions 3.1.15, 3.2.9
spip (Debian package) - update to 3.2.4-1+deb10u4
spip (Debian package) - update to 3.2.4-1+deb10u4