Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv5g-q4h3-64q4

Опубликовано: 19 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Duplicate Advisory: Hard-coded credentials in org.folio:mod-remote-storage

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-m8v7-469p-5x89. This link is maintained to preserve external references.

Original Description

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.

Пакеты

Наименование

org.folio:mod-remote-storage

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.3

2.0.3

Наименование

org.folio:mod-remote-storage

maven
Затронутые версииВерсия исправления

< 1.7.2

1.7.2

5.3 Medium

CVSS3

Дефекты

CWE-798

5.3 Medium

CVSS3

Дефекты

CWE-798