Логотип exploitDog
bind:CVE-2024-33669
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-33669

Количество 2

Количество 2

nvd логотип

CVE-2024-33669

почти 2 года назад

An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xfq4-78j7-v594

почти 2 года назад

Passbolt Browser Extension leaks password information

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-33669

An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xfq4-78j7-v594

Passbolt Browser Extension leaks password information

CVSS3: 6.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу