Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2020-26288

больше 5 лет назад

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4w46-w44m-3jq3

больше 5 лет назад

Parse Server stores password in plain text

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26288

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.

CVSS3: 7.7
1%
Низкий
больше 5 лет назад
github логотип
GHSA-4w46-w44m-3jq3

Parse Server stores password in plain text

CVSS3: 7.7
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу